vim format string flaw
Published Jul 31, 2007
6.8
MEDIUMCVSS 2.0
EPSS 4.18%
Description
Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a help-tags tag in a help file, related to the helptags command.
Affected products
No data.
- ≤ 6.4
- 7.0
- 7.1
- 7.1.38
No data.
Red Hat Enterprise Linux 3
vim-1:6.3.046-0.30E.11
Fixed · RHSA-2008:0617
Red Hat Enterprise Linux 4
vim-1:6.3.046-1.el4_7.5z
Fixed · RHSA-2008:0617
Red Hat Enterprise Linux 5
vim-2:7.0.109-4.el5_2.4z
Fixed · RHSA-2008:0580
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | vim-1:6.3.046-0.30E.11 | Fixed | RHSA-2008:0617 |
| Red Hat Enterprise Linux 4 | vim-1:6.3.046-1.el4_7.5z | Fixed | RHSA-2008:0617 |
| Red Hat Enterprise Linux 5 | vim-2:7.0.109-4.el5_2.4z | Fixed | RHSA-2008:0580 |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=248542 The Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here: https://access.redhat.com/security/updates/classification/
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.18% (0.04179) | 90.60th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.18% (0.04179) | 89.58th | v5 (v2026.06.15) |
| May 11, 2026 | 14.71% (0.14708) | 94.54th | v4 (v2025.03.14) |
| Mar 19, 2026 | 12.34% (0.12335) | 93.79th | v4 (v2025.03.14) |
| Aug 25, 2025 | 11.26% (0.11263) | 93.25th | v4 (v2025.03.14) |
| Mar 30, 2025 | 10.04% (0.10045) | 92.34th | v4 (v2025.03.14) |
| Mar 29, 2025 | 14.35% (0.14346) | 90.71th | v4 (v2025.03.14) |
| Mar 19, 2025 | 10.04% (0.10045) | 92.09th | v4 (v2025.03.14) |
| Mar 17, 2025 | 7.68% (0.07681) | 91.28th | v4 (v2025.03.14) |
| Dec 17, 2024 | 21.04% (0.21038) | 96.40th | v3 (v2023.03.01) |
| Jul 11, 2024 | 33.12% (0.33119) | 97.09th | v3 (v2023.03.01) |
| Apr 26, 2024 | 27.79% (0.27791) | 96.76th | v3 (v2023.03.01) |
| Mar 19, 2024 | 28.75% (0.28749) | 96.74th | v3 (v2023.03.01) |
| Jan 2, 2024 | 28.05% (0.28052) | 96.38th | v3 (v2023.03.01) |
| Aug 6, 2023 | 17.48% (0.17481) | 95.41th | v3 (v2023.03.01) |
| Jul 1, 2023 | 17.04% (0.17037) | 95.32th | v3 (v2023.03.01) |
| Mar 7, 2023 | 16.25% (0.16247) | 95.08th | v3 (v2023.03.01) |
| Mar 6, 2023 | 12.25% (0.12248) | 95.30th | v2 (v2022.01.01) |
| Apr 1, 2022 | 12.25% (0.12248) | 94.93th | v2 (v2022.01.01) |
| Feb 4, 2022 | 12.25% (0.12248) | 89.34th | v2 (v2022.01.01) |
No CWE recorded.
References (36)
- ftp://ftp.vim.org/pub/vim/patches/7.1/7.1.039 x_refsource_CONFIRMPatch
- http://secunia.com/advisories/25941 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/26285 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26522 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26594 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26653 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26674 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26822 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/32858 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/33410 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/secunia_research/2007-66/advisory/ x_refsource_MISCPatchVendor Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2009-001.htm x_refsource_CONFIRM
- http://www.attrition.org/pipermail/vim/2007-August/001770.html mailing-listx_refsource_VIM
- http://www.debian.org/security/2007/dsa-1364 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:168 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:236 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2007_18_sr.html vendor-advisoryx_refsource_SUSE
- http://www.redhat.com/support/errata/RHSA-2008-0580.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0617.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/475076/100/100/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/502322/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/25095 vdb-entryx_refsource_BIDPatch
- http://www.trustix.org/errata/2007/0026/ vendor-advisoryx_refsource_TRUSTIX
- http://www.ubuntu.com/usn/usn-505-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vmware.com/security/advisories/VMSA-2009-0004.html x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2007/2687 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/0033 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/0904 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2007-2953 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=248542 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35655 vdb-entryx_refsource_XF
- https://issues.rpath.com/browse/RPL-1595 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2007-2953
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11549 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6463 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2007-2953
Change history (0)
No recorded changes yet.