VIM before 6.3 and gVim before 6.3 allow local users to execute arbitrary commands via a file containing a crafted modeline that is executed when the file is viewed using options such as (1) termcap, (2) printdevice, (3) titleold, (4) filetype, (5) syntax, (6) backupext, (7) keymap, (8) patchmode, or (9) langmenu.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2004-12-22T05:00:00

Updated: 2024-08-08T00:39:00.870Z

Reserved: 2004-12-06T00:00:00

Link: CVE-2004-1138

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2005-01-10T05:00:00.000

Modified: 2017-10-11T01:29:41.920

Link: CVE-2004-1138

cve-icon Redhat

Severity : Low

Publid Date: 2004-12-15T00:00:00Z

Links: CVE-2004-1138 - Bugzilla