CVE-2008-2712

CVSS V2 High 9.3 CVSS V3 None
Description
Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properly sanitize inputs before invoking the execute or system functions, as demonstrated using (1) filetype.vim, (3) xpm.vim, (4) gzip_vim, and (5) netrw. NOTE: the originally reported version was 7.1.314, but the researcher actually found this set of issues in 7.1.298. NOTE: the zipplugin issue (originally vector 2 in this identifier) has been subsumed by CVE-2008-3075.
Overview
  • CVE ID
  • CVE-2008-2712
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2008-06-16T21:41:00
  • Last Modified Date
  • 2018-11-01T15:07:15
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:* 1 OR 6.4
cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:* 1 OR 7.0 7.1.314
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:* 1 OR
cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:lts:*:*:* 1 OR
cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:M/Au:N/C:C/I:C/A:C
  • Access Vector
  • NETWORK
  • Access Compatibility
  • MEDIUM
  • Authentication
  • NONE
  • Confidentiality Impact
  • COMPLETE
  • Integrity Impact
  • COMPLETE
  • Availability Impact
  • COMPLETE
  • Base Score
  • 9.3
  • Severity
  • HIGH
  • Exploitability Score
  • 8.6
  • Impact Score
  • 10
References
Reference URL Reference Tags
http://www.rdancer.org/vulnerablevim.html Broken Link
http://www.openwall.com/lists/oss-security/2008/06/16/2 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/29715 Third Party Advisory VDB Entry
http://secunia.com/advisories/30731 Third Party Advisory
http://www.securitytracker.com/id?1020293 Third Party Advisory VDB Entry
https://issues.rpath.com/browse/RPL-2622 Broken Link
http://wiki.rpath.com/Advisories:rPSA-2008-0247 Third Party Advisory
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html Mailing List Third Party Advisory
http://www.securityfocus.com/bid/31681 Third Party Advisory VDB Entry
http://support.apple.com/kb/HT3216 Third Party Advisory
http://secunia.com/advisories/32222 Third Party Advisory
http://secunia.com/advisories/33410 Third Party Advisory
http://support.avaya.com/elmodocs2/security/ASA-2009-001.htm Third Party Advisory
http://www.ubuntu.com/usn/USN-712-1 Third Party Advisory
http://securityreason.com/securityalert/3951 Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2008-0617.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2008-0580.html Third Party Advisory
http://marc.info/?l=bugtraq&m=121494431426308&w=2 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2008/10/15/1 Mailing List Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2008:236 Third Party Advisory
http://support.avaya.com/elmodocs2/security/ASA-2008-457.htm Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html Third Party Advisory
http://secunia.com/advisories/34418 Third Party Advisory
http://www.vmware.com/security/advisories/VMSA-2009-0004.html Third Party Advisory
http://www.vupen.com/english/advisories/2009/0904 Third Party Advisory
http://support.apple.com/kb/HT4077 Third Party Advisory
http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html Mailing List Third Party Advisory
http://www.vupen.com/english/advisories/2009/0033 Third Party Advisory
http://www.vupen.com/english/advisories/2008/1851/references Third Party Advisory
http://www.vupen.com/english/advisories/2008/2780 Third Party Advisory
http://secunia.com/advisories/32858 Third Party Advisory
http://secunia.com/advisories/32864 Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2008-0618.html Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/43083 Third Party Advisory VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6238 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11109 Third Party Advisory
http://www.securityfocus.com/archive/1/502322/100/0/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/archive/1/495319/100/0/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/archive/1/493353/100/0/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/archive/1/493352/100/0/threaded Third Party Advisory VDB Entry
History
Created Old Value New Value Data Type Notes
2022-05-10 17:54:19 Added to TrackCVE