Lucene search

K
ubuntuUbuntuUSN-505-1
HistoryAug 28, 2007 - 12:00 a.m.

vim vulnerability

2007-08-2800:00:00
ubuntu.com
30

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.1

Confidence

Low

EPSS

0.331

Percentile

97.1%

Releases

  • Ubuntu 7.04
  • Ubuntu 6.10
  • Ubuntu 6.06

Packages

  • vim -

Details

Ulf Harnhammar discovered that vim does not properly sanitise the
β€œhelptags_one()” function when running the β€œhelptags” command.
By tricking a user into running a crafted help file, a remote attacker
could execute arbitrary code with the user’s privileges.

OSVersionArchitecturePackageVersionFilename
Ubuntu7.04noarchvim<Β 1:7.0-164+1ubuntu7.2UNKNOWN
Ubuntu7.04noarchvim-common<Β 1:7.0-164+1ubuntu7.2UNKNOWN
Ubuntu7.04noarchvim-full<Β 1:7.0-164+1ubuntu7.2UNKNOWN
Ubuntu7.04noarchvim-gnome<Β 1:7.0-164+1ubuntu7.2UNKNOWN
Ubuntu7.04noarchvim-gtk<Β 1:7.0-164+1ubuntu7.2UNKNOWN
Ubuntu7.04noarchvim-perl<Β 1:7.0-164+1ubuntu7.2UNKNOWN
Ubuntu7.04noarchvim-python<Β 1:7.0-164+1ubuntu7.2UNKNOWN
Ubuntu7.04noarchvim-ruby<Β 1:7.0-164+1ubuntu7.2UNKNOWN
Ubuntu7.04noarchvim-tcl<Β 1:7.0-164+1ubuntu7.2UNKNOWN
Ubuntu7.04noarchvim-tiny<Β 1:7.0-164+1ubuntu7.2UNKNOWN
Rows per page:
1-10 of 301

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.1

Confidence

Low

EPSS

0.331

Percentile

97.1%