CVE-2002-1377
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/12/2002
Last modified:
03/04/2025
Description
vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which are not sandboxed but may be executed when vim is used to edit a malicious file, as demonstrated using mutt.
Impact
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:vim_development_group:vim:5.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:vim_development_group:vim:5.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:vim_development_group:vim:5.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:vim_development_group:vim:5.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:vim_development_group:vim:5.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:vim_development_group:vim:5.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:vim_development_group:vim:5.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:vim_development_group:vim:5.7:*:*:*:*:*:*:* | ||
cpe:2.3:a:vim_development_group:vim:5.8:*:*:*:*:*:*:* | ||
cpe:2.3:a:vim_development_group:vim:6.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:vim_development_group:vim:6.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000812
- http://lists.grok.org.uk/pipermail/full-disclosure/2002-December/002948.html
- http://marc.info/?l=bugtraq&m=108077992208690&w=2
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/55700
- http://www.guninski.com/vim1.html
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003%3A012
- http://www.redhat.com/support/errata/RHSA-2002-297.html
- http://www.redhat.com/support/errata/RHSA-2002-302.html
- http://www.securityfocus.com/bid/6384
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10835
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000812
- http://lists.grok.org.uk/pipermail/full-disclosure/2002-December/002948.html
- http://marc.info/?l=bugtraq&m=108077992208690&w=2
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/55700
- http://www.guninski.com/vim1.html
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003%3A012
- http://www.redhat.com/support/errata/RHSA-2002-297.html
- http://www.redhat.com/support/errata/RHSA-2002-302.html
- http://www.securityfocus.com/bid/6384
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10835