[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-3075Date: (C)2009-02-21   (M)2023-12-22


The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exclamation point) shell metacharacter in (1) the filename of a ZIP archive and possibly (2) the filename of the first file in a ZIP archive, which is not properly handled by zip.vim in the VIM ZIP plugin (zipPlugin.vim) v.11 through v.21, as demonstrated by the zipplugin and zipplugin.v2 test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712. NOTE: this issue has the same root cause as CVE-2008-3074. NOTE: due to the complexity of the associated disclosures and the incomplete information related to them, there may be inaccuracies in this CVE description and in external mappings to this identifier.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
http://marc.info/?l=bugtraq&m=121494431426308&w=2
BID-32463
SECUNIA-34418
MDVSA-2008:236
RHSA-2008:0580
SUSE-SR:2009:007
http://www.openwall.com/lists/oss-security/2008/07/07/4
http://www.openwall.com/lists/oss-security/2008/07/08/12
http://www.openwall.com/lists/oss-security/2008/07/10/7
http://www.openwall.com/lists/oss-security/2008/07/13/1
http://www.openwall.com/lists/oss-security/2008/07/15/4
http://www.openwall.com/lists/oss-security/2008/08/01/1
http://www.openwall.com/lists/oss-security/2008/10/15/1
http://www.openwall.com/lists/oss-security/2008/10/20/2
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506919
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0324
http://www.rdancer.org/vulnerablevim.html
https://bugzilla.redhat.com/show_bug.cgi?id=467432
oval:org.mitre.oval:def:10246

CPE    1
cpe:/a:vim:vim:7.2
CWE    1
CWE-94
OVAL    4
oval:org.secpod.oval:def:301320
oval:org.secpod.oval:def:301484
oval:org.mitre.oval:def:7596
oval:org.secpod.oval:def:600351
...

© SecPod Technologies