vulnerability
Amazon Linux AMI: CVE-2016-1248: Security patch for vim (ALAS-2016-779)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
7 | (AV:N/AC:M/Au:N/C:P/I:P/A:P) | Nov 23, 2016 | Dec 20, 2016 | Oct 14, 2022 |
Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Nov 23, 2016
Added
Dec 20, 2016
Modified
Oct 14, 2022
Description
vim before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execution of arbitrary code if a file with a specially crafted modeline is opened.
Solution
amazon-linux-upgrade-vim

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.