Vulnerability Name:

CVE-2017-1000382 (CCN-134468)

Assigned:2017-10-31
Published:2017-10-31
Updated:2017-11-27
Summary:VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the vi binary.
CVSS v3 Severity:5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
4.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
3.5 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-200
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2017-1000382

Source: CONFIRM
Type: Third Party Advisory
http://security.cucumberlinux.com/security/details.php?id=120

Source: CCN
Type: oss-sec Mailing List, Tue, 31 Oct 2017 13:23:52 +0100
20171031 Fw: Security risk of vim swap files

Source: MLIST
Type: Mailing List, Third Party Advisory
[oss-security] 20171031 Fw: Security risk of vim swap files

Source: CCN
Type: Vim Web site
welcome home : vim online

Source: XF
Type: UNKNOWN
vim-cve20171000382-info-disc(134468)

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2017-1000382

Vulnerable Configuration:Configuration 1:
  • cpe:/a:vim:vim:*:*:*:*:*:*:*:* (Version <= 8.0.1187)

  • Configuration CCN 1:
  • cpe:/a:vim:vim:8.0.1187:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20171000382
    V
    CVE-2017-1000382
    2023-06-22
    oval:org.opensuse.security:def:7902
    P
    gvim-9.0.1443-150500.18.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7825
    P
    vim-9.0.1443-150500.18.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:637
    P
    Security update for nodejs14 (Moderate) (in QA)
    2022-09-29
    oval:org.opensuse.security:def:748
    P
    Security update for samba (Important)
    2022-09-12
    oval:org.opensuse.security:def:584
    P
    Security update for nodejs12 (Important)
    2022-07-18
    oval:org.opensuse.security:def:3284
    P
    libwireshark9-2.4.16-48.51.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3218
    P
    libnghttp2-14-1.7.1-1.84 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94848
    P
    vim-8.0.1568-5.17.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94914
    P
    gvim-8.0.1568-5.17.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:328
    P
    vim-8.0.1568-5.14.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:288
    P
    python3-pip-20.0.2-6.12.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:378
    P
    vim-8.0.1568-5.17.1 on GA media (Moderate)
    2022-06-10
    oval:org.opensuse.security:def:94025
    P
    (Important)
    2022-05-16
    oval:org.opensuse.security:def:1329
    P
    Security update for the Linux Kernel (Live Patch 4 for SLE 15 SP3) (Important)
    2022-04-25
    oval:org.opensuse.security:def:1198
    P
    Security update for lapack (Moderate)
    2022-03-21
    oval:org.opensuse.security:def:973
    P
    Security update for chrony (Moderate)
    2022-03-15
    oval:org.opensuse.security:def:1440
    P
    Security update for the Linux Kernel (Live Patch 1 for SLE 15 SP3) (Important)
    2022-03-01
    oval:org.opensuse.security:def:1084
    P
    Security update for ImageMagick (Moderate)
    2022-02-21
    oval:org.opensuse.security:def:910
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:1669
    P
    Security update for qemu (Low)
    2022-01-25
    oval:org.opensuse.security:def:100738
    P
    (Moderate)
    2022-01-21
    oval:org.opensuse.security:def:112387
    P
    gvim-8.2.3408-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:1554
    P
    Security update for the Linux Kernel (Important)
    2021-11-25
    oval:org.opensuse.security:def:69956
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-11-23
    oval:org.opensuse.security:def:100679
    P
    (Important)
    2021-11-11
    oval:org.opensuse.security:def:105898
    P
    gvim-8.2.3408-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:103483
    P
    vim-8.0.1568-3.20 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:89828
    P
    vim-8.0.1568-3.20 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61673
    P
    vim-8.0.1568-3.20 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:96793
    P
    vim-8.0.1568-3.20 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71184
    P
    fuse-2.9.7-3.3.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71235
    P
    libXinerama-devel-1.1.3-1.22 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71414
    P
    vim-8.0.1568-3.20 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:49297
    P
    Security update for python-PyYAML (Important)
    2021-08-24
    oval:org.opensuse.security:def:1257
    P
    Security update for the Linux Kernel (Live Patch 4 for SLE 15 SP3) (Important)
    2021-08-17
    oval:org.opensuse.security:def:48166
    P
    libotr5-4.0.0-9.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47105
    P
    mipv6d-2.0.2.umip.0.4-19.63 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48073
    P
    libXcursor1-1.1.14-4.6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47822
    P
    logrotate-3.11.0-2.11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47598
    P
    dracut-044.1-9.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48037
    P
    guile-2.0.9-9.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46945
    P
    gdk-pixbuf-lang-2.34.0-16.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48231
    P
    libykcs11-1-1.5.0-3.16 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47106
    P
    mozilla-nspr-32bit-4.12-15.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48157
    P
    libnghttp2-14-1.7.1-1.84 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47970
    P
    chrony-2.3-5.6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47362
    P
    libjavascriptcoregtk-4_0-18-2.12.5-1.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47138
    P
    python-pyOpenSSL-16.0.0-2.3.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48262
    P
    perl-32bit-5.18.2-12.20.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47120
    P
    patch-2.7.5-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48219
    P
    libvorbis-doc-1.3.3-10.14.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47158
    P
    stunnel-5.00-3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48184
    P
    libqt4-32bit-4.8.7-8.8.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47510
    P
    syslog-service-2.0-778.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47566
    P
    bind-9.11.2-1.24 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48333
    P
    update-alternatives-1.18.4-14.216 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47241
    P
    dnsmasq-2.76-17.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48284
    P
    python-libxml2-2.9.4-46.20.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47159
    P
    sudo-1.8.10p3-6.16 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48268
    P
    perl-Mail-SpamAssassin-3.4.2-44.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47724
    P
    libjasper1-1.900.14-195.8.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47658
    P
    krb5-1.12.5-40.28.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47434
    P
    libxerces-c-3_1-3.1.1-12.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48315
    P
    supportutils-3.0.3-95.27.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47173
    P
    vorbis-tools-1.4.0-26.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48330
    P
    unixODBC-2.3.6-7.9.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47269
    P
    gnome-settings-daemon-3.20.1-49.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47808
    P
    libvpx1-1.3.0-3.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47806
    P
    libvncclient0-0.9.9-17.5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47619
    P
    giflib-progs-5.0.5-12.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47294
    P
    java-1_7_0-openjdk-1.7.0.141-42.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47270
    P
    gnome-shell-3.20.4-76.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47870
    P
    python-requests-2.11.1-6.28.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48020
    P
    glib2-lang-2.48.2-12.15.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47711
    P
    libgnomesu-2.0.0-353.6.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47487
    P
    qemu-2.9.0-5.10 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47284
    P
    gvim-7.4.326-16.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47935
    P
    zsh-5.0.5-6.7.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48104
    P
    libdjvulibre21-3.5.25.3-5.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47859
    P
    ppc64-diag-2.7.4-1.18 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47730
    P
    libkde4-32bit-4.12.0-10.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47405
    P
    libruby2_1-2_1-2.1.9-18.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47966
    P
    bubblewrap-0.3.3-1.31 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:101104
    P
    vim-8.0.1568-5.14.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101164
    P
    gvim-8.0.1568-5.14.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72087
    P
    vim-8.0.1568-5.14.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72477
    P
    gvim-8.0.1568-5.14.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62346
    P
    vim-8.0.1568-5.14.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62758
    P
    gvim-8.0.1568-5.14.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:67782
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 15) (Important)
    2021-07-27
    oval:org.opensuse.security:def:69897
    P
    Security update for linuxptp (Important)
    2021-07-27
    oval:org.opensuse.security:def:93966
    P
    (Important)
    2021-07-14
    oval:org.opensuse.security:def:64535
    P
    Security update for apache2 (Important)
    2021-06-22
    oval:org.opensuse.security:def:46824
    P
    procmail-3.22-267.12 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71071
    P
    perl-DBD-mysql-4.046-1.13 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48675
    P
    gnome-online-accounts-3.10.5-1.11 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71122
    P
    xdg-utils-20170508-3.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48729
    P
    lcms-1.19-17.31 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71118
    P
    vim-8.0.1568-3.20 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48386
    P
    coolkey-1.1.0-147.67 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48395
    P
    cups-pk-helper-0.2.5-3.72 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46809
    P
    pam_ssh-2.0-1.40 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48426
    P
    giflib-progs-5.0.5-12.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:61377
    P
    vim-8.0.1568-3.20 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46810
    P
    patch-2.7.5-7.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48497
    P
    libgoa-1_0-0-3.20.4-7.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:64484
    P
    Security update for samba (Important)
    2021-04-29
    oval:org.opensuse.security:def:70002
    P
    Security update for openssl-1_1 (Moderate)
    2021-03-09
    oval:org.opensuse.security:def:66705
    P
    Security update for ovmf (Moderate)
    2020-12-18
    oval:org.opensuse.security:def:64448
    P
    Security update for gcc7 (Moderate)
    2020-12-10
    oval:org.opensuse.security:def:73396
    P
    Security update for python-urllib3 (Moderate)
    2020-12-09
    oval:org.opensuse.security:def:64397
    P
    Security update for gcc10, nvptx-tools (Moderate)
    2020-12-04
    oval:org.opensuse.security:def:116903
    P
    vim-8.0.1568-5.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71740
    P
    vim-8.0.1568-5.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62529
    P
    gvim-8.0.1568-3.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72362
    P
    gvim-8.0.1568-5.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116962
    P
    gvim-8.0.1568-5.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:103534
    P
    gvim-8.0.1568-3.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:89879
    P
    gvim-8.0.1568-3.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61999
    P
    vim-8.0.1568-5.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62643
    P
    gvim-8.0.1568-5.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107345
    P
    vim-8.0.1568-5.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72137
    P
    gvim-8.0.1568-3.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:48971
    P
    ImageMagick-6.8.8.1-71.126.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49025
    P
    libpcap1-32bit-1.8.1-10.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107404
    P
    gvim-8.0.1568-5.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62418
    P
    gvim-8.0.1568-3.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72248
    P
    gvim-8.0.1568-3.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:66613
    P
    python3-salt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73278
    P
    patch on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49351
    P
    vim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:70061
    P
    gvim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67731
    P
    libsnmp30 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49360
    P
    xorg-x11-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67831
    P
    vim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49414
    P
    gvim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49471
    P
    libtiff5-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67882
    P
    gvim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49525
    P
    gvim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66554
    P
    libwireshark13 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73219
    P
    libsndfile-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66646
    P
    vim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49585
    P
    libxcb-render0-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49639
    P
    gvim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73337
    P
    vim on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.bionic:def:201710003820000000
    V
    CVE-2017-1000382 on Ubuntu 18.04 LTS (bionic) - low.
    2017-10-31
    oval:com.ubuntu.artful:def:20171000382000
    V
    CVE-2017-1000382 on Ubuntu 17.10 (artful) - low.
    2017-10-31
    oval:com.ubuntu.xenial:def:20171000382000
    V
    CVE-2017-1000382 on Ubuntu 16.04 LTS (xenial) - low.
    2017-10-31
    oval:com.ubuntu.xenial:def:201710003820000000
    V
    CVE-2017-1000382 on Ubuntu 16.04 LTS (xenial) - low.
    2017-10-31
    oval:com.ubuntu.bionic:def:20171000382000
    V
    CVE-2017-1000382 on Ubuntu 18.04 LTS (bionic) - low.
    2017-10-31
    oval:com.ubuntu.cosmic:def:20171000382000
    V
    CVE-2017-1000382 on Ubuntu 18.10 (cosmic) - low.
    2017-10-31
    oval:com.ubuntu.cosmic:def:201710003820000000
    V
    CVE-2017-1000382 on Ubuntu 18.10 (cosmic) - low.
    2017-10-31
    oval:com.ubuntu.trusty:def:20171000382000
    V
    CVE-2017-1000382 on Ubuntu 14.04 LTS (trusty) - low.
    2017-10-31
    BACK
    vim vim *
    vim vim 8.0.1187