Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-4677
Description:autoload/netrw.vim (aka the Netrw Plugin) 109, 131, and other versions before 133k for Vim 7.1.266, other 7.1 versions, and 7.2 stores credentials for an FTP session, and sends those credentials when attempting to establish subsequent FTP sessions to servers on different hosts, which allows remote FTP servers to obtain sensitive information in opportunistic circumstances by logging usernames and passwords. NOTE: the upstream vendor disputes a vector involving different ports on the same host, stating "I'm assuming that they're using the same id and password on that unchanged hostname, deliberately."
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-4677
BugTraq ID: 30670
http://www.securityfocus.com/bid/30670
Bugtraq: 20080812 Re: Vim: Netrw: FTP User Name and Password Disclosure (Google Search)
http://www.securityfocus.com/archive/1/495432
Bugtraq: 20080812 Vim: Netrw: FTP User Name and Password Disclosure (Google Search)
http://www.securityfocus.com/archive/1/495436
http://www.mandriva.com/security/advisories?name=MDVSA-2008:236
http://www.rdancer.org/vulnerablevim-netrw-credentials-dis.html
http://www.openwall.com/lists/oss-security/2008/10/06/4
http://www.openwall.com/lists/oss-security/2008/10/16/2
http://www.openwall.com/lists/oss-security/2008/10/20/2
http://groups.google.com/group/vim_dev/browse_thread/thread/2f6fad581a037971/a5fcf4c4981d34e6?show_docid=a5fcf4c4981d34e6
http://secunia.com/advisories/31464
http://secunia.com/advisories/34418
SuSE Security Announcement: SUSE-SR:2009:007 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html
http://www.vupen.com/english/advisories/2008/2379
XForce ISS Database: vim-netrw-ftp-information-disclosure(44419)
https://exchange.xforce.ibmcloud.com/vulnerabilities/44419




© 1998-2025 E-Soft Inc. All rights reserved.