|
Family: Ubuntu Local Security Checks --> Category: infos
USN154-1 : vim vulnerability Vulnerability Scan
Vulnerability Scan Summary vim vulnerability
Detailed Explanation for this Vulnerability Test
Synopsis :
These remote packages are missing security patches :
- kvim
- kvim-perl
- kvim-python
- kvim-tcl
- vim
- vim-common
- vim-doc
- vim-gnome
- vim-gtk
- vim-lesstif
- vim-perl
- vim-python
- vim-tcl
Description :
Georgi Guninski discovered that it was possible to construct Vim
modelines that execute arbitrary shell commands by wrapping them in
glob() or expand() function calls. If a possible hacker tricked an user to
open a file with a specially crafted modeline, he could exploit this
to execute arbitrary commands with the user's rights.
Solution :
Upgrade to :
- kvim-6.3-046+1ubuntu7.1 (Ubuntu 5.04)
- kvim-perl-6.3-046+1ubuntu7.1 (Ubuntu 5.04)
- kvim-python-6.3-046+1ubuntu7.1 (Ubuntu 5.04)
- kvim-tcl-6.3-046+1ubuntu7.1 (Ubuntu 5.04)
- vim-6.3-046+1ubuntu7.1 (Ubuntu 5.04)
- vim-common-6.3-046+1ubuntu7.1 (Ubuntu 5.04)
- vim-doc-6.3-046+1ubuntu7.1 (Ubuntu 5.04)
- vim-gnome-6.3-046+1ubuntu7.1 (Ubuntu 5.04)
- vim-gtk-6.3-046+1ubuntu7.1 (Ubuntu 5.04)
- vim-lesstif-6.3-046+1ubuntu7.1 (Ubuntu 5.04)
- vim-perl-6.3-046+1ubuntu7.1 (Ubuntu 5.04)
- vim-python-6
[...]
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|