Vim and Neovim CVE-2019-12735 Arbitrary Code Execution Vulnerability
BID:108724
CVE-2019-12735 |Info
Vim and Neovim CVE-2019-12735 Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 108724 |
| Class: | Design Error |
| CVE: |
CVE-2019-12735 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 05 2019 12:00AM |
| Updated: | Jun 05 2019 12:00AM |
| Credit: | Arminius. |
| Vulnerable: |
Vim Vim 8.1.1364 Neovim Project Neovim 0.3.5 |
| Not Vulnerable: |
Vim Vim 8.1.1365 Neovim Project Neovim 0.3.6 |
Discussion
Vim and Neovim CVE-2019-12735 Arbitrary Code Execution Vulnerability
Vim and Neovim are prone to an arbitrary code-execution vulnerability.
Successfully exploiting this issue can allow an attacker to execute arbitrary code on the affected system.
The following Vim and Neovim versions are affected:
Vim versions prior to 8.1.1365 are vulnerable.
Neovim versions prior to 0.3.6 are vulnerable.
Vim and Neovim are prone to an arbitrary code-execution vulnerability.
Successfully exploiting this issue can allow an attacker to execute arbitrary code on the affected system.
The following Vim and Neovim versions are affected:
Vim versions prior to 8.1.1365 are vulnerable.
Neovim versions prior to 0.3.6 are vulnerable.
Exploit / POC
Vim and Neovim CVE-2019-12735 Arbitrary Code Execution Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
Vim and Neovim CVE-2019-12735 Arbitrary Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Vim and Neovim CVE-2019-12735 Arbitrary Code Execution Vulnerability
References:
References:
- CVE-2019-12735 vim/neovim: arbitrary command execution in getchar.c (Red Hat)
- Neovim Homepage (neovim)
- neovim: CVE-2019-12735: Modelines allow arbitrary code execution (Debian)
- patch 8.1.1365: source command doesn't check for the sandbox (Github)
- Vim < 8.1.1365 / Neovim < 0.3.6 - Arbitrary Code Execution (Exploit DB)
- VIM Homepage (VIM Development Group)
- vim-patch:8.1.1365: :source should check sandbox #10082 (Github)
- Vim/Neovim Arbitrary Code Execution via Modelines (Github)
- vim: CVE-2019-12735: Modelines allow arbitrary code execution (Debian)
- USN-4016-1: Vim vulnerabilities (Ubuntu)
- USN-4016-2: Neovim vulnerability (Ubuntu)