[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

VIM - (bulletinjul2018)

ID: oval:org.secpod.oval:def:2102702Date: (C)2019-12-31   (M)2024-02-19
Class: PATCHFamily: unix




fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor"s primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.

Platform:
Sun Solaris 11
Product:
editor/vim
editor/vim/vim-core
editor/gvim
Reference:
bulletinjul2018
CVE-2017-17087
CVE    1
CVE-2017-17087
CPE    1
cpe:/o:oracle:solaris:11

© SecPod Technologies