fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade vim | Aug 6, 2019 | Dec 1, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade vim-enhancedUpgrade vim-filesystemUpgrade vim-minimalUpgrade vim-common | Dec 4, 2019 | Dec 1, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade vim-commonUpgrade vim-filesystemUpgrade vim-minimalUpgrade vim-enhanced | Dec 18, 2019 | Dec 1, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade vim-commonUpgrade vim-filesystemUpgrade vim-minimalUpgrade vim-enhanced | Feb 24, 2020 | Dec 1, 2017 |
| Oracle Solaris | — | Upgrade editor/vim to version 8.1.209-11.4.1.0.1.2.0 on Solaris 11.4Upgrade editor/vim/vim-core to version 8.1.209-11.4.1.0.1.2.0 on Solaris 11.4Upgrade editor/gvim to version 8.1.209-11.4.1.0.1.2.0 on Solaris 11.4 | Oct 19, 2018 | Dec 1, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 4, 2017 |
| Suse | — | Upgrade vim-dataUpgrade vim-smallUpgrade vim-data-commonUpgrade vimUpgrade gvim | Aug 9, 2024 | Dec 1, 2017 |
| Ubuntu | — | Upgrade vim-runtimeUpgrade vim (Ubuntu Pro)Upgrade vim-commonUpgrade vim | Oct 15, 2020 | Dec 1, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 1, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub