Oval Definition:oval:com.ubuntu.disco:def:2019127350000000
Revision Date:2019-06-05Version:1
Title:CVE-2019-12735 on Ubuntu 19.04 (disco) - medium.
Description:getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim. It was discovered that Vim incorrectly handled certain files. An attacker could possibly use this issue to execute arbitrary code.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-12735
Platform(s):Ubuntu 19.04
Product(s):
Definition Synopsis
  • Ubuntu 19.04 (disco) is installed.
  • AND Package Information
  • neovim package in disco was vulnerable but has been fixed (note: '0.3.4-1ubuntu0.19.04.1').
  • OR vim package in disco was vulnerable but has been fixed (note: '2:8.1.0320-1ubuntu3.1').
  • BACK