CVE-2009-0316

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983), as demonstrated by an erroneous search path for plugin/bike.vim in bicyclerepair.

References

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=484305

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=493937

http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html

http://support.apple.com/kb/HT4077

http://www.mandriva.com/security/advisories?name=MDVSA-2009:047

http://www.nabble.com/Bug-484305%3A-bicyclerepair%3A-bike.vim-imports-untrusted-python-files-from-cwd-td18848099.html

http://www.openwall.com/lists/oss-security/2009/01/26/2

http://www.securityfocus.com/bid/33447

https://bugzilla.redhat.com/show_bug.cgi?id=481565

https://exchange.xforce.ibmcloud.com/vulnerabilities/48275

https://svn.pardus.org.tr/pardus/2008/applications/editors/vim/files/official/7.2.045

Details

Source: MITRE

Published: 2009-01-28

Updated: 2017-08-08

Risk Information

CVSS v2

Base Score: 6.9

Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.4

Severity: MEDIUM

Tenable Plugins

View all (6 total)

IDNameProductFamilySeverity
51524RHEL 5 : python (RHSA-2011:0027)NessusRed Hat Local Security Checks
high
45373Mac OS X Multiple Vulnerabilities (Security Update 2010-002)NessusMacOS X Local Security Checks
critical
40230openSUSE Security Update : gvim (gvim-561)NessusSuSE Local Security Checks
high
39980openSUSE Security Update : gvim (gvim-561)NessusSuSE Local Security Checks
high
36407Mandriva Linux Security Advisory : vim (MDVSA-2009:047-1)NessusMandriva Local Security Checks
medium
35921openSUSE 10 Security Update : gvim (gvim-6023)NessusSuSE Local Security Checks
high