vim: Lack of validation of values for few options results in code exection
Published Nov 23, 2016
7.8
HIGHCVSS 3.0
EPSS 25.31%
Description
vim before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execution of arbitrary code if a file with a specially crafted modeline is opened.
Affected products
- Vendor n/a Product Vim Before Patch 8.0.0056 Defaultn/a
- Version vim before patch 8.0.0056StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Vim Before Patch 8.0.0056 | n/a |
|
Configuration 2
- 8.0
No data.
Red Hat Enterprise Linux 6
vim-2:7.4.629-5.el6_8.1
Fixed · RHSA-2016:2972
Red Hat Enterprise Linux 7
vim-2:7.4.160-1.el7_3.1
Fixed · RHSA-2016:2972
Red Hat Enterprise Linux 5
vim
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | vim-2:7.4.629-5.el6_8.1 | Fixed | RHSA-2016:2972 |
| Red Hat Enterprise Linux 7 | vim-2:7.4.160-1.el7_3.1 | Fixed | RHSA-2016:2972 |
| Red Hat Enterprise Linux 5 | vim | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Disabling modeline support in .vimrc by adding "set nomodeline" will prevent exploitation of this flaw. By default, modeline is enabled for ordinary users but disabled for root.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 25.31% (0.25314) | 97.88th | v5 (v2026.06.15) |
| Sep 22, 2026 | 25.31% (0.25314) | 97.84th | v5 (v2026.06.15) |
| Sep 21, 2026 | 7.66% (0.07664) | 94.40th | v5 (v2026.06.15) |
| Sep 6, 2026 | 25.31% (0.25314) | 97.80th | v5 (v2026.06.15) |
| Sep 5, 2026 | 7.66% (0.07664) | 94.28th | v5 (v2026.06.15) |
| Aug 30, 2026 | 25.31% (0.25314) | 97.78th | v5 (v2026.06.15) |
| Aug 28, 2026 | 7.66% (0.07664) | 94.24th | v5 (v2026.06.15) |
| Aug 24, 2026 | 25.31% (0.25314) | 97.77th | v5 (v2026.06.15) |
| Aug 23, 2026 | 7.66% (0.07664) | 94.21th | v5 (v2026.06.15) |
| Jun 15, 2026 | 25.50% (0.25504) | 97.68th | v5 (v2026.06.15) |
| Dec 29, 2025 | 15.94% (0.15939) | 94.54th | v4 (v2025.03.14) |
| Mar 17, 2025 | 23.18% (0.23182) | 95.48th | v4 (v2025.03.14) |
| Jan 21, 2025 | 76.38% (0.76381) | 98.43th | v3 (v2023.03.01) |
| Dec 23, 2024 | 67.88% (0.67884) | 98.13th | v3 (v2023.03.01) |
| Dec 17, 2024 | 71.72% (0.71717) | 98.25th | v3 (v2023.03.01) |
| Jul 11, 2024 | 80.97% (0.80973) | 98.36th | v3 (v2023.03.01) |
| Mar 7, 2023 | 80.03% (0.80025) | 97.72th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.44% (0.02444) | 81.63th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.44% (0.02444) | 79.88th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.44% (0.02444) | 58.47th | v2 (v2022.01.01) |
References (17)
- http://openwall.com/lists/oss-security/2016/11/22/20 x_refsource_CONFIRMPatchThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2972.html vendor-advisoryx_refsource_REDHAT
- http://www.debian.org/security/2016/dsa-3722 vendor-advisoryx_refsource_DEBIAN
- http://www.securityfocus.com/bid/94478 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1037338 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/USN-3139-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2016-1248 Vendor Advisory
- https://anonscm.debian.org/cgit/pkg-vim/vim.git/tree/debian/changelog x_refsource_CONFIRMPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1398227 Issue Tracking
- https://github.com/neovim/neovim/commit/4fad66fbe637818b6b3d6bc5d21923ba72795040 x_refsource_CONFIRMPatchVendor Advisory
- https://github.com/vim/vim/commit/d0b5138ba4bccff8a744c99836041ef6322ed39a x_refsource_CONFIRMPatchVendor Advisory
- https://github.com/vim/vim/releases/tag/v8.0.0056 x_refsource_CONFIRMPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2016/11/msg00025.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-security-announce/2016/msg00305.html x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-1248
- https://security.gentoo.org/glsa/201701-29 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2016-1248
Change history (0)
No recorded changes yet.