Amazon Linux 2 : vim (ALAS-2019-1239)
High Nessus Plugin ID 127460
Synopsis
The remote Amazon Linux 2 host is missing a security update.
Description
It was found that the `:source!` command was not restricted by the sandbox mode. If modeline was explicitly enabled, opening a specially crafted text file in vim could result in arbitrary command execution.
(CVE-2019-12735)
Solution
Run 'yum update 'vim*'' to update your system.