fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade vim | Aug 6, 2019 | Dec 1, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade vim-enhancedUpgrade vim-minimalUpgrade vim-filesystemUpgrade vim-common | Dec 4, 2019 | Dec 1, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade vim-filesystemUpgrade vim-commonUpgrade vim-enhancedUpgrade vim-minimal | Dec 18, 2019 | Dec 1, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade vim-enhancedUpgrade vim-filesystemUpgrade vim-commonUpgrade vim-minimal | Feb 24, 2020 | Dec 1, 2017 |
| Oracle Solaris | — | Upgrade editor/gvim to version 8.1.209-11.4.1.0.1.2.0 on Solaris 11.4Upgrade editor/vim/vim-core to version 8.1.209-11.4.1.0.1.2.0 on Solaris 11.4Upgrade editor/vim to version 8.1.209-11.4.1.0.1.2.0 on Solaris 11.4 | Oct 19, 2018 | Dec 1, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 4, 2017 |
| Suse | — | Upgrade vim-data-commonUpgrade vim-smallUpgrade vimUpgrade gvimUpgrade vim-data | Aug 9, 2024 | Dec 1, 2017 |
| Ubuntu | — | Upgrade vimUpgrade vim-commonUpgrade vim (Ubuntu Pro)Upgrade vim-runtime | Oct 15, 2020 | Dec 1, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 1, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub