CVE-2017-1000382

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the vi binary.

References

http://security.cucumberlinux.com/security/details.php?id=120

http://www.openwall.com/lists/oss-security/2017/10/31/1

Details

Source: MITRE

Published: 2017-10-31

Updated: 2017-11-27

Type: CWE-200

Risk Information

CVSS v2

Base Score: 2.1

Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 3.9

Severity: LOW

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Impact Score: 3.6

Exploitability Score: 1.8

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:* versions up to 8.0.1187 (inclusive)

Tenable Plugins

View all (4 total)

IDNameProductFamilySeverity
121973Photon OS 2.0: Vim PHSA-2018-2.0-0076NessusPhotonOS Local Security Checks
medium
121867Photon OS 1.0: Vim PHSA-2018-1.0-0167NessusPhotonOS Local Security Checks
critical
111960Photon OS 2.0: Blktrace / Systemd / Vim PHSA-2018-2.0-0076 (deprecated)NessusPhotonOS Local Security Checks
medium
111946Photon OS 1.0: Blktrace / Libmspack / Ntp / Openjdk / Perl / Systemd / Vim PHSA-2018-1.0-0167 (deprecated)NessusPhotonOS Local Security Checks
critical