Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Ubuntu 16.10: USN-3139-1 Critical: Vim Code Execution Risk

ubuntu
Calendar Grey November 29, 2016
Scroller Ubuntu
Ubuntu Security Notice USN-8234-2 highlights a critical issue in Git that could enable unauthorized data access. Discover the steps to remedy this situation promptly.
Vim could be made run programs as your login if it opened a speciallycrafted file.

Summary

Vim could be made run programs as your login if it opened a specially

crafted file.

Software Description:

- vim: Vi IMproved - enhanced vi editor

Details:

Florian Larysch discovered that the Vim text editor did not properly

validate values for the 'filetype', 'syntax', and 'keymap' options. An

attacker could trick a user into opening a file with specially crafted

modelines and possibly execute arbitrary code with the user's privileges.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.10:
  vim                             2:7.4.1829-1ubuntu2.1
  vim-common                      2:7.4.1829-1ubuntu2.1
  vim-gui-common                  2:7.4.1829-1ubuntu2.1
  vim-runtime                     2:7.4.1829-1ubuntu2.1

Ubuntu 16.04 LTS:
  vim                             2:7.4.1689-3ubuntu1.2
  vim-common                      2:7.4.1689-3ubuntu1.2
  vim-gui-common                  2:7.4.1689-3ubuntu1.2
  vim-runtime                     2:7.4.1689-3ubuntu1.2

Ubuntu 14.04 LTS:
  vim                             2:7.4.052-1ubuntu3.1
  vim-common                      2:7.4.052-1ubuntu3.1
  vim-gui-common                  2:7.4.052-1ubuntu3.1
  vim-runtime                     2:7.4.052-1ubuntu3.1

Ubuntu 12.04 LTS:
  vim                             2:7.3.429-2ubuntu2.2
  vim-common                      2:7.3.429-2ubuntu2.2
  vim-gui-common                  2:7.3.429-2ubuntu2.2
  vim-runtime                     2:7.3.429-2ubuntu2.2

After a standard system update you need to restart Vim to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-3139-1

CVE-2016-1248

Severity
critical
Lowest
Low
Medium
High
Critical

November 29, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.