Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.51333
Kategorie:Conectiva Local Security Checks
Titel:Conectiva Security Advisory CLA-2004:812
Zusammenfassung:NOSUMMARY
Beschreibung:Description:

The remote host is missing updates announced in
advisory CLA-2004:812.

Vim is a highly configurable text editor. It is an improved version
of the vi editor distributed with most UNIX systems.

Georgi Guninski found[1] a vulnerability[2] in vim that can be
exploited to execute arbitrary commands when the user opens a text
file specially crafted by an attacker. The vulnerability resides in
the modelines feature, which allows one to place some VIM commands
inside of a text file.

This update includes a new version of vim (6.1+patches) which,
besides the fix for the aforementioned vulnerability, contains
several other bug fixes. The vim package distributed with Conectiva
Linux 9 (vim-*-6.1-27650cl) is already patched and therefore not
vulnerable to this issue.


Solution:
The apt tool can be used to perform RPM package upgrades
by running 'apt-get update' followed by 'apt-get upgrade'

http://www.guninski.com/vim1.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1377
http://www.securityspace.com/smysecure/catid.html?in=CLA-2004:812
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=002004

Risk factor : Medium

CVSS Score:
4.6

Querverweis: BugTraq ID: 6384
Common Vulnerability Exposure (CVE) ID: CVE-2002-1377
http://www.securityfocus.com/bid/6384
Bugtraq: 20040331 OpenLinux: vim arbitrary commands execution through modelines (Google Search)
http://marc.info/?l=bugtraq&m=108077992208690&w=2
Conectiva Linux advisory: CLA-2004:812
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000812
http://lists.grok.org.uk/pipermail/full-disclosure/2002-December/002948.html
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:012
http://www.guninski.com/vim1.html
http://www.redhat.com/support/errata/RHSA-2002-297.html
http://www.redhat.com/support/errata/RHSA-2002-302.html
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/55700
XForce ISS Database: vim-modeline-command-execution(10835)
https://exchange.xforce.ibmcloud.com/vulnerabilities/10835
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.