Package : vim
Vulnerability : several
Problem-Type : local(remote)
Debian-specific: no
CVE ID : CVE-2007-2438 CVE-2007-2953
Several vulnerabilities have been discovered in the vim editor. The Common
Vulnerabilities and Exposures project identifies the following problems:
CVE-2007-2953
Ulf Harnhammar discovered that a format string flaw in helptags_one() from
src/ex_cmds.c (triggered through the "helptags" command) can lead to the
execution of arbitrary code.
CVE-2007-2438
Editors often provide a way to embed editor configuration commands (aka
modelines) which are executed once a file is opened. Harmful commands
are filtered by a sandbox mechanism. It was discovered that function
calls to writefile(), feedkeys() and system() were not filtered, allowing
shell command execution with a carefully crafted file opened in vim.
This updated advisory repairs issues with missing files in the packages
for the oldstable distribution (sarge) for the alpha, mips, and mipsel
architectures.
For the oldstable distribution (sarge) these problems have been fixed in
version 6.3-071+1sarge2. Sarge is not affected by CVE-2007-2438.
For the stable distribution (etch) these problems have been fixed
in version 7.0-122+1etch3.
For the unstable distribution (sid) these problems have been fixed in
version 7.1-056+1.
These files will probably be moved into the stable distribution on
its next update.
- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFG8aBfhuANDBmkLRkRAi3cAKCU7KewVmGTkGGuRbzoE3kmxPf6fgCgjTOe
k+dEjfg/eP+mr6669LdzT4E=
=PeLq
-----END PGP SIGNATURE----- Received on Thu Sep 20 12:26:38 2007
This archive was generated by hypermail 2.1.8
: Sun Oct 28 2007 - 06:16:30 EDT