Vulnerability Name: CVE-2008-4101 (CCN-44626) Assigned: 2008-08-19 Published: 2008-08-19 Updated: 2018-10-11 Summary: Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) followed by a command, or execute arbitrary Ex commands by entering an argument after a (2) "Ctrl-]" (control close-square-bracket) or (3) "g]" (g close-square-bracket) keystroke sequence, a different issue than CVE-2008-2712 . CVSS v3 Severity: 4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): HighPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): LowAvailibility (A): None
CVSS v2 Severity: 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C )7.3 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N )3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N/E:POC/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): HighAthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): None
Vulnerability Type: CWE-20 Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2008-4101 Source: MLIST Type: Exploit[vim-dev] 20080903 Patch 7.2.010 Source: MISC Type: UNKNOWNhttp://groups.google.com/group/vim_dev/attach/9290f26f9bc11b33/K-arbitrary-command-execution.patch.v3?part=2 Source: MISC Type: Patchhttp://groups.google.com/group/vim_dev/attach/dd32ad3a84f36bb2/K-arbitrary-command-execution.patch?part=2 Source: CCN Type: Google Groups, vin_dev, Aug 19, 11:38 pmBug with v_K and potentially K command Source: MISC Type: Exploithttp://groups.google.com/group/vim_dev/browse_thread/thread/1434d0812b5c817e/6ad2d5b50a96668e Source: MLIST Type: Patch[vim_dev] 20080824 Bug with v_K and potentially K command Source: APPLE Type: UNKNOWNAPPLE-SA-2008-10-09 Source: APPLE Type: UNKNOWNAPPLE-SA-2010-03-29-1 Source: CCN Type: RHSA-2008-0580Moderate: vim security update Source: CCN Type: RHSA-2008-0617Moderate: vim security update Source: CCN Type: RHSA-2008-0618Moderate: vim security update Source: CCN Type: SA31592Vim Shell Command Injection Weaknesses Source: SECUNIA Type: UNKNOWN31592 Source: CCN Type: SA32222Apple Mac OS X Security Update Fixes Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN32222 Source: SECUNIA Type: UNKNOWN32858 Source: SECUNIA Type: UNKNOWN32864 Source: CCN Type: SA33410Avaya Products Vim Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN33410 Source: CONFIRM Type: UNKNOWNhttp://support.apple.com/kb/HT3216 Source: CCN Type: Apple Web siteAbout the security content of Security Update 2010-002 / Mac OS X v10.6.3 Source: CONFIRM Type: UNKNOWNhttp://support.apple.com/kb/HT4077 Source: CONFIRM Type: UNKNOWNhttp://support.avaya.com/elmodocs2/security/ASA-2008-457.htm Source: CCN Type: ASA-2008-457vim security update (RHSA-2008-0618) Source: CONFIRM Type: UNKNOWNhttp://support.avaya.com/elmodocs2/security/ASA-2009-001.htm Source: CCN Type: ASA-2009-001vim security update (RHSA-2008-0617) Source: DEBIAN Type: DSA-1733vim -- several vulnerabilities Source: MANDRIVA Type: UNKNOWNMDVSA-2008:236 Source: MLIST Type: UNKNOWN[oss-security] 20080911 [oss-list] CVE request (vim) Source: MLIST Type: UNKNOWN[oss-security] 20080911 Re: [oss-list] CVE request (vim) Source: MLIST Type: UNKNOWN[oss-security] 20080915 Re: [oss-list] CVE request (vim) Source: MLIST Type: UNKNOWN[oss-security] 20080915 Re: [oss-list] CVE request (vim) Source: CCN Type: rdancer Advisories, 2008-08-20Arbitrary Code Execution in Commands: K, Control-], g] Source: MISC Type: UNKNOWNhttp://www.rdancer.org/vulnerablevim-K.html Source: REDHAT Type: UNKNOWNRHSA-2008:0580 Source: REDHAT Type: UNKNOWNRHSA-2008:0617 Source: REDHAT Type: UNKNOWNRHSA-2008:0618 Source: BUGTRAQ Type: UNKNOWN20080822 Vim: Arbitrary Code Execution in Commands: K, Control-], g] Source: BUGTRAQ Type: UNKNOWN20080825 RE: Arbitrary Code Execution in Commands: K, Control-], g] Source: BUGTRAQ Type: UNKNOWN20090401 VMSA-2009-0004 ESX Service Console updates for openssl, bind, and vim Source: BID Type: UNKNOWN30795 Source: CCN Type: BID-30795Vim Insufficient Shell Escaping Multiple Command Execution Vulnerabilities Source: BID Type: UNKNOWN31681 Source: CCN Type: BID-31681RETIRED: Apple Mac OS X 2008-007 Multiple Security Vulnerabilities Source: CCN Type: USN-712-1Vim vulnerabilities Source: UBUNTU Type: UNKNOWNUSN-712-1 Source: CCN Type: Vim Web sitewelcome home : vim online Source: CCN Type: VMSA-2009-0004ESX Service Console updates for openssl, bind, and vim Source: CONFIRM Type: UNKNOWNhttp://www.vmware.com/security/advisories/VMSA-2009-0004.html Source: VUPEN Type: UNKNOWNADV-2008-2780 Source: VUPEN Type: UNKNOWNADV-2009-0033 Source: VUPEN Type: UNKNOWNADV-2009-0904 Source: CONFIRM Type: UNKNOWNhttps://bugzilla.redhat.com/show_bug.cgi?id=461927 Source: XF Type: UNKNOWNvim-normal-command-execution(44626) Source: XF Type: UNKNOWNvim-normal-command-execution(44626) Source: OVAL Type: UNKNOWNoval:org.mitre.oval:def:10894 Source: OVAL Type: UNKNOWNoval:org.mitre.oval:def:5812 Vulnerable Configuration: Configuration 1 :cpe:/a:vim:vim:3.0:*:*:*:*:*:*:* OR cpe:/a:vim:vim:4.0:*:*:*:*:*:*:* OR cpe:/a:vim:vim:5.0:*:*:*:*:*:*:* OR cpe:/a:vim:vim:5.1:*:*:*:*:*:*:* OR cpe:/a:vim:vim:5.2:*:*:*:*:*:*:* OR cpe:/a:vim:vim:5.3:*:*:*:*:*:*:* OR cpe:/a:vim:vim:5.4:*:*:*:*:*:*:* OR cpe:/a:vim:vim:5.5:*:*:*:*:*:*:* OR cpe:/a:vim:vim:5.6:*:*:*:*:*:*:* OR cpe:/a:vim:vim:5.7:*:*:*:*:*:*:* OR cpe:/a:vim:vim:5.8:*:*:*:*:*:*:* OR cpe:/a:vim:vim:6.0:*:*:*:*:*:*:* OR cpe:/a:vim:vim:6.1:*:*:*:*:*:*:* OR cpe:/a:vim:vim:6.2:*:*:*:*:*:*:* OR cpe:/a:vim:vim:6.3:*:*:*:*:*:*:* OR cpe:/a:vim:vim:6.4:*:*:*:*:*:*:* OR cpe:/a:vim:vim:7.0:*:*:*:*:*:*:* OR cpe:/a:vim:vim:7.1:*:*:*:*:*:*:* OR cpe:/a:vim:vim:*:*:*:*:*:*:*:* (Version <= 7.2) Configuration RedHat 1 :cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:* Configuration RedHat 2 :cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:* Configuration RedHat 3 :cpe:/o:redhat:enterprise_linux:5::server:*:*:*:*:* Configuration RedHat 4 :cpe:/o:redhat:enterprise_linux:4:*:*:*:*:*:*:* Configuration RedHat 5 :cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:* Configuration RedHat 6 :cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:* Configuration RedHat 7 :cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:* Configuration RedHat 8 :cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:* Configuration CCN 1 :cpe:/a:vim:vim:6.0:*:*:*:*:*:*:* OR cpe:/a:vim:vim:6.1:*:*:*:*:*:*:* OR cpe:/a:vim:vim:6.3:*:*:*:*:*:*:* OR cpe:/a:vim:vim:6.4:*:*:*:*:*:*:* OR cpe:/a:vim:vim:5.0:*:*:*:*:*:*:* OR cpe:/a:vim:vim:7.0:*:*:*:*:*:*:* OR cpe:/a:vim:vim:7.1:*:*:*:*:*:*:* OR cpe:/a:vim:vim:7.2:*:*:*:*:*:*:* OR cpe:/a:vim:vim:3.0:*:*:*:*:*:*:* OR cpe:/a:vim:vim:4.0:*:*:*:*:*:*:* OR cpe:/a:vim:vim:5.1:*:*:*:*:*:*:* OR cpe:/a:vim:vim:5.2:*:*:*:*:*:*:* OR cpe:/a:vim:vim:5.3:*:*:*:*:*:*:* OR cpe:/a:vim:vim:5.4:*:*:*:*:*:*:* OR cpe:/a:vim:vim:5.5:*:*:*:*:*:*:* OR cpe:/a:vim:vim:5.6:*:*:*:*:*:*:* OR cpe:/a:vim:vim:5.7:*:*:*:*:*:*:* OR cpe:/a:vim:vim:5.8:*:*:*:*:*:*:* OR cpe:/a:vim:vim:6.2:*:*:*:*:*:*:* AND cpe:/o:redhat:enterprise_linux:2.1:*:as:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:2.1:*:es:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:2.1:*:ws:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:3::ws:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:3::es:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:3::as:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:3::desktop:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0:*:*:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:* OR cpe:/a:mandrakesoft:mandrake_multi_network_firewall:2.0:*:*:*:*:*:*:* OR cpe:/o:redhat:linux_advanced_workstation:2.1:*:itanium:*:*:*:*:* OR cpe:/o:canonical:ubuntu:6.06:*:lts:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:*:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:x86_64:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0:*:x86_64:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux:2008.0:*:x86-64:*:*:*:*:* OR cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:5:*:client:*:*:*:*:* OR cpe:/o:canonical:ubuntu:7.10:*:*:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux:2008.0:*:*:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux:2008.1:x86_64:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.5:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5.1:*:*:*:*:*:*:* OR cpe:/a:vmware:esx_server:2.5.5:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux:2008.1:*:*:*:*:*:*:* OR cpe:/o:canonical:ubuntu:8.04:*:lts:*:*:*:*:* OR cpe:/a:vmware:esx_server:3.5:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5.3:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.5.3:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.5.4:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5.4:*:*:*:*:*:*:* OR cpe:/a:vmware:esx_server:3.0.3:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.5.5:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5.5:*:*:*:*:*:*:* OR cpe:/o:mandriva:linux:2009.0:*:*:*:*:*:*:* OR cpe:/o:mandriva:linux:2009.0:-:x86_64:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.5.8:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5.8:*:*:*:*:*:*:* Denotes that component is vulnerable Oval Definitions BACK
vim vim 3.0
vim vim 4.0
vim vim 5.0
vim vim 5.1
vim vim 5.2
vim vim 5.3
vim vim 5.4
vim vim 5.5
vim vim 5.6
vim vim 5.7
vim vim 5.8
vim vim 6.0
vim vim 6.1
vim vim 6.2
vim vim 6.3
vim vim 6.4
vim vim 7.0
vim vim 7.1
vim vim *
vim vim 6.0
vim vim 6.1
vim vim 6.3
vim vim 6.4
vim vim 5.0
vim vim 7.0
vim vim 7.1
vim vim 7.2
vim vim 3.0
vim vim 4.0
vim vim 5.1
vim vim 5.2
vim vim 5.3
vim vim 5.4
vim vim 5.5
vim vim 5.6
vim vim 5.7
vim vim 5.8
vim vim 6.2
redhat enterprise linux 2.1
redhat enterprise linux 2.1
redhat enterprise linux 2.1
redhat enterprise linux 3
redhat enterprise linux 3
redhat enterprise linux 3
redhat enterprise linux 3
mandrakesoft mandrake linux corporate server 3.0
redhat enterprise linux 4
redhat enterprise linux 4
redhat enterprise linux 4
redhat enterprise linux 4
mandrakesoft mandrake multi network firewall 2.0
redhat linux advanced workstation 2.1
canonical ubuntu 6.06
mandrakesoft mandrake linux corporate server 4.0
mandrakesoft mandrake linux corporate server 4.0
mandrakesoft mandrake linux corporate server 3.0
redhat enterprise linux 5
mandrakesoft mandrake linux 2008.0
debian debian linux 4.0
redhat enterprise linux 5
canonical ubuntu 7.10
mandrakesoft mandrake linux 2008.0
mandrakesoft mandrake linux 2008.1 x86_64
apple mac os x 10.5
apple mac os x server 10.5
apple mac os x 10.5.1
apple mac os x server 10.5.1
vmware esx server 2.5.5
apple mac os x 10.5.2
apple mac os x server 10.5.2
mandrakesoft mandrake linux 2008.1
canonical ubuntu 8.04
vmware esx server 3.5
apple mac os x server 10.5.3
apple mac os x 10.5.3
apple mac os x 10.5.4
apple mac os x server 10.5.4
vmware esx server 3.0.3
apple mac os x 10.5.5
apple mac os x server 10.5.5
mandriva linux 2009.0
mandriva linux 2009.0 -
apple mac os x 10.5.8
apple mac os x server 10.5.8