Vulnerability Name: CVE-2004-1138 (CCN-18503) Assigned: 2004-12-15 Published: 2004-12-15 Updated: 2017-10-11 Summary: VIM before 6.3 and gVim before 6.3 allow local users to execute arbitrary commands via a file containing a crafted modeline that is executed when the file is viewed using options such as (1) termcap, (2) printdevice, (3) titleold, (4) filetype, (5) syntax, (6) backupext, (7) keymap, (8) patchmode, or (9) langmenu. CVSS v3 Severity: 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
CVSS v2 Severity: 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
Vulnerability Type: CWE-Other Vulnerability Consequences: Gain Privileges References: Source: MITRE Type: CNACVE-2004-1138 Source: OPENPKG Type: UNKNOWNOpenPKG-SA-2004.052 Source: CCN Type: RHSA-2005-010vim security update Source: CCN Type: RHSA-2005-036vim security update Source: CCN Type: VIM Download Web pagedownload : vim online Source: CCN Type: CIAC Information Bulletin P-090VIM Modeline Vulnerability Source: CCN Type: GLSA-200412-10Vim, gVim: Vulnerable options in modelines Source: GENTOO Type: Patch, Vendor AdvisoryGLSA-200412-10 Source: CCN Type: OpenPKG-SA-2004.052Vim Source: REDHAT Type: UNKNOWNRHSA-2005:010 Source: REDHAT Type: UNKNOWNRHSA-2005:036 Source: CCN Type: BID-11941Vim Modelines Arbitrary Command Execution Variant Vulnerability Source: CCN Type: USN-52-1vim vulnerability Source: FEDORA Type: UNKNOWNFLSA:2343 Source: XF Type: UNKNOWNvim-modeline-gain-privileges(18503) Source: XF Type: UNKNOWNvim-modeline-gain-privileges(18503) Source: OVAL Type: UNKNOWNoval:org.mitre.oval:def:9571 Vulnerable Configuration: Configuration 1 :cpe:/a:vim_development_group:vim:5.0:*:*:*:*:*:*:* OR cpe:/a:vim_development_group:vim:5.1:*:*:*:*:*:*:* OR cpe:/a:vim_development_group:vim:5.2:*:*:*:*:*:*:* OR cpe:/a:vim_development_group:vim:5.3:*:*:*:*:*:*:* OR cpe:/a:vim_development_group:vim:5.4:*:*:*:*:*:*:* OR cpe:/a:vim_development_group:vim:5.5:*:*:*:*:*:*:* OR cpe:/a:vim_development_group:vim:5.6:*:*:*:*:*:*:* OR cpe:/a:vim_development_group:vim:5.7:*:*:*:*:*:*:* OR cpe:/a:vim_development_group:vim:5.8:*:*:*:*:*:*:* OR cpe:/a:vim_development_group:vim:6.0:*:*:*:*:*:*:* OR cpe:/a:vim_development_group:vim:6.1:*:*:*:*:*:*:* OR cpe:/a:vim_development_group:vim:6.2:*:*:*:*:*:*:* OR cpe:/a:vim_development_group:vim:6.3.011:*:*:*:*:*:*:* OR cpe:/a:vim_development_group:vim:6.3.025:*:*:*:*:*:*:* OR cpe:/a:vim_development_group:vim:6.3.030:*:*:*:*:*:*:* OR cpe:/a:vim_development_group:vim:6.3.044:*:*:*:*:*:*:* Configuration RedHat 1 :cpe:/o:redhat:enterprise_linux:*:*:*:*:*:*:*:* Denotes that component is vulnerable Oval Definitions Definition ID Class Title Last Modified oval:org.mitre.oval:def:9571 V VIM before 6.3 and gVim before 6.3 allow local users to execute arbitrary commands via a file containing a crafted modeline that is executed when the file is viewed using options such as (1) termcap, (2) printdevice, (3) titleold, (4) filetype, (5) syntax, (6) backupext, (7) keymap, (8) patchmode, or (9) langmenu. 2013-04-29 oval:com.redhat.rhsa:def:20050036 P RHSA-2005:036: vim security update (Low) 2005-02-15 oval:com.redhat.rhsa:def:20050010 P RHSA-2005:010: vim security update (Low) 2005-01-05
BACK
vim_development_group vim 5.0
vim_development_group vim 5.1
vim_development_group vim 5.2
vim_development_group vim 5.3
vim_development_group vim 5.4
vim_development_group vim 5.5
vim_development_group vim 5.6
vim_development_group vim 5.7
vim_development_group vim 5.8
vim_development_group vim 6.0
vim_development_group vim 6.1
vim_development_group vim 6.2
vim_development_group vim 6.3.011
vim_development_group vim 6.3.025
vim_development_group vim 6.3.030
vim_development_group vim 6.3.044