Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.50497
Category:Ubuntu Local Security Checks
Title:Ubuntu 4.10 USN-61-1 (vim)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to vim
announced via advisory USN-61-1.

Javier Fernandez-Sanguino Pena noticed that the auxillary scripts
'tcltags' and 'vimspell.sh' created temporary files in an insecure
manner. This could allow a symbolic link attack to create or overwrite
arbitrary files with the privileges of the user invoking the script
(either by calling it directly or by execution through vim).

The following packages are affected:

kvim
vim
vim-gnome
vim-gtk
vim-lesstif
vim-perl
vim-python
vim-tcl

Solution:
The problem can be corrected by upgrading the affected package to
version 1:6.3-025+1ubuntu2.2. In general, a standard system upgrade is
sufficient to effect the necessary changes.

http://lists.ubuntu.com/archives/ubuntu-security-announce/2005-January/000063.html

Risk factor : Medium

CVSS Score:
4.6

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2005-0069
Bugtraq: 20050118 [USN-61-1] vim vulnerabilities (Google Search)
http://marc.info/?l=bugtraq&m=110608387001863&w=2
https://bugzilla.fedora.us/show_bug.cgi?id=2343
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9402
http://www.redhat.com/support/errata/RHSA-2005-036.html
http://www.redhat.com/support/errata/RHSA-2005-122.html
http://securitytracker.com/id?1012938
http://secunia.com/advisories/13841/
XForce ISS Database: vim-symlink(18870)
https://exchange.xforce.ibmcloud.com/vulnerabilities/18870
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.