Oval Definition:oval:org.mitre.oval:def:22692
Revision Date:2014-05-26Version:36
Title:ELSA-2008:0580: vim security update (Moderate)
Description:The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a filename used by the (1) "D" (delete) command or (2) b:netrw_curdir variable, as demonstrated using the netrw.v4 and netrw.v5 test cases.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2007-2953
CVE-2008-2712
CVE-2008-3074
CVE-2008-3075
CVE-2008-4101
CVE-2008-6235
ELSA-2008:0580-01
Platform(s):Oracle Linux 5
Product(s):vim
Definition Synopsis
  • Oracle Linux 5.x
  • AND rpm test
  • vim-minimal is earlier than 2:7.0.109-4.el5_2.4z
  • OR vim is earlier than 2:7.0.109-4.el5_2.4z
  • OR vim-X11 is earlier than 2:7.0.109-4.el5_2.4z
  • OR vim-common is earlier than 2:7.0.109-4.el5_2.4z
  • OR vim-enhanced is earlier than 2:7.0.109-4.el5_2.4z
  • BACK