vim: arbitrary code execution in commands: K, Control-], g]
Published Sep 18, 2008
9.3
HIGHCVSS 2.0
EPSS 9.21%
Description
Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) followed by a command, or execute arbitrary Ex commands by entering an argument after a (2) "Ctrl-]" (control close-square-bracket) or (3) "g]" (g close-square-bracket) keystroke sequence, a different issue than CVE-2008-2712.
Affected products
No data.
- ≤ 7.2
- 3.0
- 4.0
- 5.0
- 5.1
- 5.2
- 5.3
- 5.4
- 5.5
- 5.6
- 5.7
- 5.8
- 6.0
- 6.1
- 6.2
- 6.3
- 6.4
- 7.0
- 7.1
No data.
Red Hat Enterprise Linux 2.1
vim-1:6.0-7.25
Fixed · RHSA-2008:0618
Red Hat Enterprise Linux 3
vim-1:6.3.046-0.30E.11
Fixed · RHSA-2008:0617
Red Hat Enterprise Linux 4
vim-1:6.3.046-1.el4_7.5z
Fixed · RHSA-2008:0617
Red Hat Enterprise Linux 5
vim-2:7.0.109-4.el5_2.4z
Fixed · RHSA-2008:0580
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 2.1 | vim-1:6.0-7.25 | Fixed | RHSA-2008:0618 |
| Red Hat Enterprise Linux 3 | vim-1:6.3.046-0.30E.11 | Fixed | RHSA-2008:0617 |
| Red Hat Enterprise Linux 4 | vim-1:6.3.046-1.el4_7.5z | Fixed | RHSA-2008:0617 |
| Red Hat Enterprise Linux 5 | vim-2:7.0.109-4.el5_2.4z | Fixed | RHSA-2008:0580 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (42)
- http://ftp.vim.org/pub/vim/patches/7.2/7.2.010 mailing-listx_refsource_MLISTExploit
- http://groups.google.com/group/vim_dev/attach/9290f26f9bc11b33/K-arbitrary-command-execution.patch.v3?part=2 x_refsource_MISC
- http://groups.google.com/group/vim_dev/attach/dd32ad3a84f36bb2/K-arbitrary-command-execution.patch?part=2 x_refsource_MISCPatch
- http://groups.google.com/group/vim_dev/browse_thread/thread/1434d0812b5c817e/6ad2d5b50a96668e x_refsource_MISCExploit
- http://groups.google.com/group/vim_dev/msg/9290f26f9bc11b33 mailing-listx_refsource_MLISTPatch
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html vendor-advisoryx_refsource_APPLE
- http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html vendor-advisoryx_refsource_APPLE
- http://secunia.com/advisories/31592 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/32222 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/32858 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/32864 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/33410 third-party-advisoryx_refsource_SECUNIA
- http://support.apple.com/kb/HT3216 x_refsource_CONFIRM
- http://support.apple.com/kb/HT4077 x_refsource_CONFIRM
- http://support.avaya.com/elmodocs2/security/ASA-2008-457.htm x_refsource_CONFIRM
- http://support.avaya.com/elmodocs2/security/ASA-2009-001.htm x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:236 vendor-advisoryx_refsource_MANDRIVA
- http://www.openwall.com/lists/oss-security/2008/09/11/3 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2008/09/11/4 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2008/09/16/5 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2008/09/16/6 mailing-listx_refsource_MLIST
- http://www.rdancer.org/vulnerablevim-K.html x_refsource_MISC
- http://www.redhat.com/support/errata/RHSA-2008-0580.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0617.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0618.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/495662 mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/495703 mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/502322/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/30795 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/31681 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-712-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vmware.com/security/advisories/VMSA-2009-0004.html x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2008/2780 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/0033 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/0904 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2008-4101 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=461927 x_refsource_CONFIRMIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44626 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2008-4101
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10894 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5812 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2008-4101
Change history (0)
No recorded changes yet.