The sandbox for vim allows dangerous functions such as (1) writefile, (2) feedkeys, and (3) system, which might allow user-assisted attackers to execute shell commands and write files via modelines.
References
Link Providers
http://attrition.org/pipermail/vim/2007-May/001614.html cve-icon cve-icon
http://marc.info/?l=vim-dev&m=117762581821298&w=2 cve-icon cve-icon
http://marc.info/?l=vim-dev&m=117778983714029&w=2 cve-icon cve-icon
http://osvdb.org/36250 cve-icon cve-icon
http://secunia.com/advisories/25024 cve-icon cve-icon
http://secunia.com/advisories/25159 cve-icon cve-icon
http://secunia.com/advisories/25182 cve-icon cve-icon
http://secunia.com/advisories/25255 cve-icon cve-icon
http://secunia.com/advisories/25367 cve-icon cve-icon
http://secunia.com/advisories/25432 cve-icon cve-icon
http://secunia.com/advisories/26653 cve-icon cve-icon
http://tech.groups.yahoo.com/group/vimannounce/message/178 cve-icon cve-icon
http://tech.groups.yahoo.com/group/vimdev/message/46627 cve-icon cve-icon
http://tech.groups.yahoo.com/group/vimdev/message/46645 cve-icon cve-icon
http://tech.groups.yahoo.com/group/vimdev/message/46658 cve-icon cve-icon
http://www.attrition.org/pipermail/vim/2007-August/001770.html cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1364 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:101 cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_12_sr.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0346.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/467202/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/23725 cve-icon cve-icon
http://www.securitytracker.com/id?1018035 cve-icon cve-icon
http://www.trustix.org/errata/2007/0017/ cve-icon cve-icon
http://www.ubuntu.com/usn/usn-463-1 cve-icon cve-icon
http://www.vim.org/news/news.php cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/1599 cve-icon cve-icon
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=238259 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/34012 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-2438 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9876 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-2438 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2007-05-02T21:00:00

Updated: 2024-08-07T13:42:32.149Z

Reserved: 2007-05-01T00:00:00

Link: CVE-2007-2438

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-05-02T21:19:00.000

Modified: 2024-11-21T00:30:47.127

Link: CVE-2007-2438

cve-icon Redhat

Severity : Moderate

Publid Date: 2007-04-26T00:00:00Z

Links: CVE-2007-2438 - Bugzilla