VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the vi binary.
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | No solution exists | May 15, 2025 | May 15, 2025 |
| Oracle Solaris | — | Upgrade editor/gvim to version 8.1.209-11.4.1.0.1.2.0 on Solaris 11.4Upgrade editor/vim/vim-core to version 8.1.209-11.4.1.0.1.2.0 on Solaris 11.4Upgrade editor/vim to version 8.1.209-11.4.1.0.1.2.0 on Solaris 11.4 | Oct 19, 2018 | Oct 31, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 31, 2017 |
| Suse | — | Upgrade vim-dataUpgrade vimUpgrade gvimUpgrade vim-smallUpgrade vim-data-common | May 19, 2018 | Oct 31, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 31, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub