Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2002-1377
Description:vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which are not sandboxed but may be executed when vim is used to edit a malicious file, as demonstrated using mutt.
Test IDs: 1.3.6.1.4.1.25623.1.0.51333   1.3.6.1.4.1.25623.1.0.50676   1.3.6.1.4.1.25623.1.0.51209  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2002-1377
BugTraq ID: 6384
http://www.securityfocus.com/bid/6384
Bugtraq: 20040331 OpenLinux: vim arbitrary commands execution through modelines (Google Search)
http://marc.info/?l=bugtraq&m=108077992208690&w=2
Conectiva Linux advisory: CLA-2004:812
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000812
http://lists.grok.org.uk/pipermail/full-disclosure/2002-December/002948.html
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:012
http://www.guninski.com/vim1.html
RedHat Security Advisories: RHSA-2002:297
http://www.redhat.com/support/errata/RHSA-2002-297.html
RedHat Security Advisories: RHSA-2002:302
http://www.redhat.com/support/errata/RHSA-2002-302.html
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/55700
XForce ISS Database: vim-modeline-command-execution(10835)
https://exchange.xforce.ibmcloud.com/vulnerabilities/10835




© 1998-2025 E-Soft Inc. All rights reserved.