Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.51333
Categoría:Conectiva Local Security Checks
Título:Conectiva Security Advisory CLA-2004:812
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing updates announced in
advisory CLA-2004:812.

Vim is a highly configurable text editor. It is an improved version
of the vi editor distributed with most UNIX systems.

Georgi Guninski found[1] a vulnerability[2] in vim that can be
exploited to execute arbitrary commands when the user opens a text
file specially crafted by an attacker. The vulnerability resides in
the modelines feature, which allows one to place some VIM commands
inside of a text file.

This update includes a new version of vim (6.1+patches) which,
besides the fix for the aforementioned vulnerability, contains
several other bug fixes. The vim package distributed with Conectiva
Linux 9 (vim-*-6.1-27650cl) is already patched and therefore not
vulnerable to this issue.


Solution:
The apt tool can be used to perform RPM package upgrades
by running 'apt-get update' followed by 'apt-get upgrade'

http://www.guninski.com/vim1.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1377
http://www.securityspace.com/smysecure/catid.html?in=CLA-2004:812
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=002004

Risk factor : Medium

CVSS Score:
4.6

Referencia Cruzada: BugTraq ID: 6384
Common Vulnerability Exposure (CVE) ID: CVE-2002-1377
http://www.securityfocus.com/bid/6384
Bugtraq: 20040331 OpenLinux: vim arbitrary commands execution through modelines (Google Search)
http://marc.info/?l=bugtraq&m=108077992208690&w=2
Conectiva Linux advisory: CLA-2004:812
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000812
http://lists.grok.org.uk/pipermail/full-disclosure/2002-December/002948.html
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:012
http://www.guninski.com/vim1.html
http://www.redhat.com/support/errata/RHSA-2002-297.html
http://www.redhat.com/support/errata/RHSA-2002-302.html
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/55700
XForce ISS Database: vim-modeline-command-execution(10835)
https://exchange.xforce.ibmcloud.com/vulnerabilities/10835
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.