Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) followed by a command, or execute arbitrary Ex commands by entering an argument after a (2) "Ctrl-]" (control close-square-bracket) or (3) "g]" (g close-square-bracket) keystroke sequence, a different issue than CVE-2008-2712.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Vim | — | Apply OS X security update 2010-002 | Dec 16, 2011 | Sep 18, 2008 |
| Centos_linux | — | Upgrade vim-minimalUpgrade vim-X11Upgrade vim-commonUpgrade vim-enhanced | Dec 1, 2016 | Sep 18, 2008 |
| Debian | — | Upgrade vim | Jul 30, 2024 | Sep 18, 2008 |
| Oracle_linux | — | Upgrade vim-X11Upgrade vim-enhancedUpgrade vim-commonUpgrade vim-minimal | Oct 16, 2024 | Sep 18, 2008 |
| Suse | — | Upgrade gvim | Dec 12, 2013 | Sep 18, 2008 |
| Ubuntu | — | Upgrade vimUpgrade vim-runtime | Nov 8, 2024 | Sep 18, 2008 |
| Vmsa 2009 0004 | — | Upgrade VMware ESX 3.5 to build number 158874 | Nov 19, 2010 | Sep 18, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub