Back

LOW

vim: insecure temporary file usage in configure script

Published Jul 24, 2008

Description

src/configure.in in Vim 5.0 through 7.1, when used for a build with Python support, does not ensure that the Makefile-conf temporary file has the intended ownership and permissions, which allows local users to execute arbitrary code by modifying this file during a time window, or by creating it ahead of time with permissions that prevent its modification by configure.

Affected products

Remediation

Red Hat statement

This issue can only be exploited during the package build and it does not affect users of pre-built packages distributed with Red Hat Enterprise Linux. Therefore, we do not plan to backport a fix for this issue to already released version of Red Hat Enterprise Linux 2.1, 3, 4, and 5.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 24, 2008
Updated Aug 7, 2024
Reserved Jul 24, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date Jul 17, 2008