Vulnerability Name: | CVE-2008-6235 (CCN-43871) | ||||||||||||||||||||||||
Assigned: | 2008-07-15 | ||||||||||||||||||||||||
Published: | 2008-07-15 | ||||||||||||||||||||||||
Updated: | 2017-09-29 | ||||||||||||||||||||||||
Summary: | The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a filename used by the (1) "D" (delete) command or (2) b:netrw_curdir variable, as demonstrated using the netrw.v4 and netrw.v5 test cases. | ||||||||||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.6 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:UR)
4.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:UR)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-78 | ||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
References: | Source: CCN Type: BugTraq Mailing List, Wed Jul 16 2008 - 06:53:29 CDT Arbitrary code execution in Netrw version 127, Vim 7.2b Source: MITRE Type: CNA CVE-2008-6235 Source: SUSE Type: UNKNOWN SUSE-SR:2009:007 Source: CCN Type: RHSA-2008-0580 Moderate: vim security update Source: SECUNIA Type: UNKNOWN 34418 Source: MLIST Type: Exploit [oss-security] 20081016 CVE request - Vim netrw.plugin Source: MLIST Type: UNKNOWN [oss-security] 20081020 CVE request (vim) Source: CCN Type: OSVDB ID: 52164 Vim Netrw Plugin (netrw.vim) Filename Metacharacter Arbitrary Command Execution Source: MISC Type: Exploit, Patch, Vendor Advisory http://www.rdancer.org/vulnerablevim-netrw.html Source: MISC Type: Patch http://www.rdancer.org/vulnerablevim-netrw.v2.html Source: CCN Type: rdancer Advisories, 2008-07-03 Arbitrary code execution in Netrw version 127, Vim 7.2b Source: MISC Type: Exploit, Vendor Advisory http://www.rdancer.org/vulnerablevim-netrw.v5.html Source: REDHAT Type: UNKNOWN RHSA-2008:0580 Source: CCN Type: BID-30254 Netrw Vim Script 's:BrowserMaps()' Command Execution Vulnerability Source: CCN Type: Vim Web site netrw.vim - Network oriented reading, writing, and browsing (keywords: netrw ftp scp) : vim online Source: XF Type: UNKNOWN netrw-sbrowsermaps-code-execution(43871) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11247 Source: SUSE Type: SUSE-SR:2009:007 SUSE Security Summary Report | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration CCN 1: ![]() | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |