Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Gentoo: 200302-14 Urgent: Gnome Terminal Command Execution Issue

gentoo
Calendar Grey January 22, 2003
Dist Gentoo Esm H88
A significant vulnerability in Vim's command execution could lead to unauthorized exploitation. It is advisable to update to the most recent version to reduce threats and boost security.
Opening a specially crafted text file with vim can execute arbitrary shell commands and pass parameters to them.

Summary


- - --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200301-13
- - --------------------------------------------------------------------
DATE    : 2003-01-22 11:48 UTC

- - --------------------------------------------------------------------
- From advisory:
"Opening a specially crafted text file with vim can execute arbitrary shell commands and pass parameters to them."
Read the full advisory at /vim1.html
SOLUTION
It is recommended that all Gentoo Linux users who are running affected versions of app-editors/{vim,vim-core,gvim} upgrade as follows:
emerge sync
If you are running app-editos/vim-core upgrade to vim-core-6.1-r4 :
emerge -u vim-core
If you are running app-editos/vim upgrade to vim-6.1-r19 :
emerge -u vim
If you are running app-editos/gvim upgrade to gvim-6.1-r6 :
emerge -u gvim
emerge clean
...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : vim vim-core gvim
SUMMARY : arbitrary code execution
EXPLOIT : remote

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here