Vim Feedkeys and Writefile Functions Remote Code Execution Vulnerabilities
BID:23725
Info
Vim Feedkeys and Writefile Functions Remote Code Execution Vulnerabilities
| Bugtraq ID: | 23725 |
| Class: | Design Error |
| CVE: |
CVE-2007-2438 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 30 2007 12:00AM |
| Updated: | Sep 20 2007 04:20PM |
| Credit: | Tomas Golembiovsky reported these issues. |
| Vulnerable: |
VIM Development Group VIM 7.0 Trustix Secure Linux 3.0.5 Trustix Secure Linux 3.0 S.u.S.E. openSUSE 10.2 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Foresight Linux Foresight Linux 1.1 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: | |
Discussion
Vim Feedkeys and Writefile Functions Remote Code Execution Vulnerabilities
Vim is prone to multiple vulnerabilities that permit a remote attacker to execute arbitrary code.
The attacker could exploit these issues by enticing a victim to load a malicious file. A successful exploit could allow arbitrary code to run within the context of the affected application.
Vim is prone to multiple vulnerabilities that permit a remote attacker to execute arbitrary code.
The attacker could exploit these issues by enticing a victim to load a malicious file. A successful exploit could allow arbitrary code to run within the context of the affected application.
Exploit / POC
Vim Feedkeys and Writefile Functions Remote Code Execution Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Vim Feedkeys and Writefile Functions Remote Code Execution Vulnerabilities
Solution:
The vendor released patches to address these issues. Please see the references for more information.
VIM Development Group VIM 7.0
Solution:
The vendor released patches to address these issues. Please see the references for more information.
VIM Development Group VIM 7.0
-
Mandriva vim-common-7.0-16.1mdv2007.0.i586.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download -
Mandriva vim-common-7.0-16.1mdv2007.0.x86_64.rpm
Mandriva Linux 2007.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva vim-common-7.0-16.1mdv2007.1.i586.rpm
Mandriva Linux 2007.1:
http://www.mandriva.com/en/download -
Mandriva vim-common-7.0-16.1mdv2007.1.x86_64.rpm
Mandriva Linux 2007.1/X86_64:
http://www.mandriva.com/en/download -
Mandriva vim-enhanced-7.0-16.1mdv2007.0.i586.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download -
Mandriva vim-enhanced-7.0-16.1mdv2007.0.x86_64.rpm
Mandriva Linux 2007.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva vim-enhanced-7.0-16.1mdv2007.1.i586.rpm
Mandriva Linux 2007.1:
http://www.mandriva.com/en/download -
Mandriva vim-enhanced-7.0-16.1mdv2007.1.x86_64.rpm
Mandriva Linux 2007.1/X86_64:
http://www.mandriva.com/en/download -
Mandriva vim-minimal-7.0-16.1mdv2007.0.i586.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download -
Mandriva vim-minimal-7.0-16.1mdv2007.0.x86_64.rpm
Mandriva Linux 2007.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva vim-minimal-7.0-16.1mdv2007.1.i586.rpm
Mandriva Linux 2007.1:
http://www.mandriva.com/en/download -
Mandriva vim-minimal-7.0-16.1mdv2007.1.x86_64.rpm
Mandriva Linux 2007.1/X86_64:
http://www.mandriva.com/en/download -
Mandriva vim-X11-7.0-16.1mdv2007.0.i586.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download -
Mandriva vim-X11-7.0-16.1mdv2007.0.x86_64.rpm
Mandriva Linux 2007.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva vim-X11-7.0-16.1mdv2007.1.i586.rpm
Mandriva Linux 2007.1:
http://www.mandriva.com/en/download -
Mandriva vim-X11-7.0-16.1mdv2007.1.x86_64.rpm
Mandriva Linux 2007.1/X86_64:
http://www.mandriva.com/en/download -
VIM Development Group patch 7.0.234
ftp://ftp.vim.org/pub/vim/patches/7.0/7.0.234 -
VIM Development Group patch 7.0.235
ftp://ftp.vim.org/pub/vim/patches/7.0/7.0.235
References
Vim Feedkeys and Writefile Functions Remote Code Execution Vulnerabilities
References:
References:
- VIM Homepage (VIM Development Group)
- vim: feedkeys() and writefile() allowed in sandbox CVE-unassigned (rPath Linux)
- feedkeys() allowed in sandbox (Thomas Golembiovsky )
- RHSA-2007:0346-3 vim security update (Red Hat)