Oval Definition:oval:com.ubuntu.bionic:def:2019127350000000
Revision Date:2019-06-05Version:1
Title:CVE-2019-12735 on Ubuntu 18.04 LTS (bionic) - medium.
Description:getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim. It was discovered that Vim incorrectly handled certain files. An attacker could possibly use this issue to execute arbitrary code.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-12735
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND Package Information
  • neovim package in bionic is affected and needs fixing.
  • OR vim package in bionic was vulnerable but has been fixed (note: '2:8.0.1453-1ubuntu1.1').
  • BACK