Oval Definition:oval:com.redhat.rhsa:def:20080617
Revision Date:2008-11-25Version:648
Title:RHSA-2008:0617: vim security update (Moderate)
Description:Vim (Visual editor IMproved) is an updated and improved version of the vi editor.

  • Several input sanitization flaws were found in Vim's keyword and tag handling. If Vim looked up a document's maliciously crafted tag or keyword, it was possible to execute arbitrary code as the user running Vim. (CVE-2008-4101)

  • A heap-based overflow flaw was discovered in Vim's expansion of file name patterns with shell wildcards. An attacker could create a specially-crafted file or directory name that, when opened by Vim, caused the application to crash or, possibly, execute arbitrary code. (CVE-2008-3432)

  • Several input sanitization flaws were found in various Vim system functions. If a user opened a specially crafted file, it was possible to execute arbitrary code as the user running Vim. (CVE-2008-2712)

  • Ulf Härnhammar, of Secunia Research, discovered a format string flaw in Vim's help tag processor. If a user was tricked into executing the "helptags" command on malicious data, arbitrary code could be executed with the permissions of the user running Vim. (CVE-2007-2953)

    All Vim users are advised to upgrade to these updated packages, which contain backported patches to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2007-2953
    CVE-2008-2712
    CVE-2008-3432
    CVE-2008-4101
    RHSA-2008:0617
    RHSA-2008:0617-01
    RHSA-2008:0617-01
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • vim-minimal is earlier than 1:6.3.046-0.30E.11
  • AND vim-minimal is signed with Red Hat master key
  • vim-common is earlier than 1:6.3.046-0.30E.11
  • AND vim-common is signed with Red Hat master key
  • vim-X11 is earlier than 1:6.3.046-0.30E.11
  • AND vim-X11 is signed with Red Hat master key
  • vim-enhanced is earlier than 1:6.3.046-0.30E.11
  • AND vim-enhanced is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • vim-common is earlier than 1:6.3.046-1.el4_7.5z
  • AND vim-common is signed with Red Hat master key
  • vim-enhanced is earlier than 1:6.3.046-1.el4_7.5z
  • AND vim-enhanced is signed with Red Hat master key
  • vim-minimal is earlier than 1:6.3.046-1.el4_7.5z
  • AND vim-minimal is signed with Red Hat master key
  • vim-X11 is earlier than 1:6.3.046-1.el4_7.5z
  • AND vim-X11 is signed with Red Hat master key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • vim is earlier than 1:6.3.046-0.30E.11
  • AND vim is signed with Red Hat master key
  • vim-X11 is earlier than 1:6.3.046-0.30E.11
  • AND vim-X11 is signed with Red Hat master key
  • vim-common is earlier than 1:6.3.046-0.30E.11
  • AND vim-common is signed with Red Hat master key
  • vim-enhanced is earlier than 1:6.3.046-0.30E.11
  • AND vim-enhanced is signed with Red Hat master key
  • vim-minimal is earlier than 1:6.3.046-0.30E.11
  • AND vim-minimal is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • vim is earlier than 1:6.3.046-1.el4_7.5z
  • AND vim is signed with Red Hat master key
  • vim-X11 is earlier than 1:6.3.046-1.el4_7.5z
  • AND vim-X11 is signed with Red Hat master key
  • vim-common is earlier than 1:6.3.046-1.el4_7.5z
  • AND vim-common is signed with Red Hat master key
  • vim-enhanced is earlier than 1:6.3.046-1.el4_7.5z
  • AND vim-enhanced is signed with Red Hat master key
  • vim-minimal is earlier than 1:6.3.046-1.el4_7.5z
  • AND vim-minimal is signed with Red Hat master key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • vim-X11 is earlier than 1:6.3.046-1.el4_7.5z
  • AND vim-X11 is signed with Red Hat redhatrelease2 key
  • vim-common is earlier than 1:6.3.046-1.el4_7.5z
  • AND vim-common is signed with Red Hat redhatrelease2 key
  • vim-enhanced is earlier than 1:6.3.046-1.el4_7.5z
  • AND vim-enhanced is signed with Red Hat redhatrelease2 key
  • vim-minimal is earlier than 1:6.3.046-1.el4_7.5z
  • AND vim-minimal is signed with Red Hat redhatrelease2 key
  • BACK