Oval Definition:oval:com.redhat.rhsa:def:20080580
Revision Date:2008-11-25Version:653
Title:RHSA-2008:0580: vim security update (Moderate)
Description:Vim (Visual editor IMproved) is an updated and improved version of the vi editor.

  • Several input sanitization flaws were found in Vim's keyword and tag handling. If Vim looked up a document's maliciously crafted tag or keyword, it was possible to execute arbitrary code as the user running Vim. (CVE-2008-4101)

  • Multiple security flaws were found in netrw.vim, the Vim plug-in providing file reading and writing over the network. If a user opened a specially crafted file or directory with the netrw plug-in, it could result in arbitrary code execution as the user running Vim. (CVE-2008-3076)

  • A security flaw was found in zip.vim, the Vim plug-in that handles ZIP archive browsing. If a user opened a ZIP archive using the zip.vim plug-in, it could result in arbitrary code execution as the user running Vim. (CVE-2008-3075)

  • A security flaw was found in tar.vim, the Vim plug-in which handles TAR archive browsing. If a user opened a TAR archive using the tar.vim plug-in, it could result in arbitrary code execution as the user runnin Vim. (CVE-2008-3074)

  • Several input sanitization flaws were found in various Vim system functions. If a user opened a specially crafted file, it was possible to execute arbitrary code as the user running Vim. (CVE-2008-2712)

  • Ulf Härnhammar, of Secunia Research, discovered a format string flaw in Vim's help tag processor. If a user was tricked into executing the "helptags" command on malicious data, arbitrary code could be executed with the permissions of the user running Vim. (CVE-2007-2953)

    All Vim users are advised to upgrade to these updated packages, which contain backported patches to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2007-2953
    CVE-2008-2712
    CVE-2008-3074
    CVE-2008-3075
    CVE-2008-4101
    CVE-2008-6235
    RHSA-2008:0580
    RHSA-2008:0580-01
    RHSA-2008:0580-01
    Platform(s):Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • vim-X11 is earlier than 2:7.0.109-4.el5_2.4z
  • AND vim-X11 is signed with Red Hat redhatrelease2 key
  • vim-common is earlier than 2:7.0.109-4.el5_2.4z
  • AND vim-common is signed with Red Hat redhatrelease2 key
  • vim-enhanced is earlier than 2:7.0.109-4.el5_2.4z
  • AND vim-enhanced is signed with Red Hat redhatrelease2 key
  • vim-minimal is earlier than 2:7.0.109-4.el5_2.4z
  • AND vim-minimal is signed with Red Hat redhatrelease2 key
  • BACK