CVE-2007-2953

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/07/2007
Last modified:
09/04/2025

Description

Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a help-tags tag in a help file, related to the helptags command.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vim_development_group:vim:*:*:*:*:*:*:*:* 6.4 (including)
cpe:2.3:a:vim_development_group:vim:7.0:*:*:*:*:*:*:*
cpe:2.3:a:vim_development_group:vim:7.1:*:*:*:*:*:*:*
cpe:2.3:a:vim_development_group:vim:7.1.38:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools