CVE-2018-11319
Summary
| CVE | CVE-2018-11319 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-20 20:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potentially the root). This improper handling might be exploited for arbitrary code execution via a malicious gcc plugin, if an attacker has write access to a directory that is a parent of the base directory of the project being checked. NOTE: exploitation is more difficult after 3.8.0 because filename prediction may be needed. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Syntastic Project | Syntastic | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| #894736 - vim-syntastic: CVE-2018-11319: Checker config files allow arbitrary code execution scenarios - Debian Bug report logs | MISC | bugs.debian.org | Exploit, Issue Tracking, Third Party Advisory |
| [SECURITY] [DLA 1444-1] vim-syntastic security update | MLIST | lists.debian.org | Mailing List, Third Party Advisory |
| Debian -- Security Information -- DSA-4261-1 vim-syntastic | DEBIAN | www.debian.org | Third Party Advisory |
| Checker config files allow arbitrary code execution scenarios · Issue #2170 · vim-syntastic/syntastic · GitHub | MISC | github.com | Exploit, Issue Tracking, Third Party Advisory |
| Security: clear defaults for config file names (cf. #2170). · vim-syntastic/syntastic@6d7c0b3 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.