ALT-PU-2019-2207-1
Closed vulnerabilities
Published: 2019-06-05
BDU:2019-03251
Уязвимость библиотеки getchar.c текстового редактора Vim, связанная с отсутствием мер по нейтрализации специальных элементов, используемых в команде операционной системы, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Severity: HIGH (8.6)
Vector: AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
References:
Published: 2019-06-05
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-12735
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.
Severity: HIGH (8.6)
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
References:
- openSUSE-SU-2019:1551
- openSUSE-SU-2019:1551
- openSUSE-SU-2019:1562
- openSUSE-SU-2019:1562
- openSUSE-SU-2019:1561
- openSUSE-SU-2019:1561
- openSUSE-SU-2019:1759
- openSUSE-SU-2019:1759
- openSUSE-SU-2019:1796
- openSUSE-SU-2019:1796
- openSUSE-SU-2019:1997
- openSUSE-SU-2019:1997
- 108724
- 108724
- RHSA-2019:1619
- RHSA-2019:1619
- RHSA-2019:1774
- RHSA-2019:1774
- RHSA-2019:1793
- RHSA-2019:1793
- RHSA-2019:1947
- RHSA-2019:1947
- https://bugs.debian.org/930020
- https://bugs.debian.org/930020
- https://bugs.debian.org/930024
- https://bugs.debian.org/930024
- https://github.com/neovim/neovim/pull/10082
- https://github.com/neovim/neovim/pull/10082
- https://github.com/numirias/security/blob/master/doc/2019-06-04_ace-vim-neovim.md
- https://github.com/numirias/security/blob/master/doc/2019-06-04_ace-vim-neovim.md
- https://github.com/vim/vim/commit/53575521406739cf20bbe4e384d88e7dca11f040
- https://github.com/vim/vim/commit/53575521406739cf20bbe4e384d88e7dca11f040
- [debian-lts-announce] 20190803 [SECURITY] [DLA 1871-1] vim security update
- [debian-lts-announce] 20190803 [SECURITY] [DLA 1871-1] vim security update
- FEDORA-2019-d79f89346c
- FEDORA-2019-d79f89346c
- FEDORA-2019-dcd49378b8
- FEDORA-2019-dcd49378b8
- 20190724 [SECURITY] [DSA 4487-1] neovim security update
- 20190724 [SECURITY] [DSA 4487-1] neovim security update
- 20190624 [SECURITY] [DSA 4467-2] vim regression update
- 20190624 [SECURITY] [DSA 4467-2] vim regression update
- GLSA-202003-04
- GLSA-202003-04
- https://support.f5.com/csp/article/K93144355
- https://support.f5.com/csp/article/K93144355
- https://support.f5.com/csp/article/K93144355?utm_source=f5support&%3Butm_medium=RSS
- https://support.f5.com/csp/article/K93144355?utm_source=f5support&%3Butm_medium=RSS
- USN-4016-1
- USN-4016-1
- USN-4016-2
- USN-4016-2
- DSA-4467
- DSA-4467
- DSA-4487
- DSA-4487