Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983), as demonstrated by an erroneous search path for plugin/bike.vim in bicyclerepair.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Vim | — | Apply OS X security update 2010-002 | Dec 16, 2011 | Jan 28, 2009 |
| Debian | — | Upgrade vim | Jul 30, 2024 | Jan 28, 2009 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 6, 2008 |
| Suse | — | Upgrade vim-smallUpgrade vimUpgrade vim-dataUpgrade vim-data-commonUpgrade xxdUpgrade gvim | Dec 12, 2013 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub