The sandbox for vim allows dangerous functions such as (1) writefile, (2) feedkeys, and (3) system, which might allow user-assisted attackers to execute shell commands and write files via modelines.

Project Subscriptions

Vendors Products
Foresight Linux Subscribe
Foresight Linux Subscribe
Enterprise Linux Subscribe
Vim Development Group Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-1364-1 New vim packages fix several vulnerabilities
Debian DSA Debian DSA DSA-1364-2 New vim packages fix several vulnerabilities
EUVD EUVD EUVD-2007-2433 The sandbox for vim allows dangerous functions such as (1) writefile, (2) feedkeys, and (3) system, which might allow user-assisted attackers to execute shell commands and write files via modelines.
Ubuntu USN Ubuntu USN USN-463-1 vim vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://attrition.org/pipermail/vim/2007-May/001614.html cve-icon cve-icon
http://marc.info/?l=vim-dev&m=117762581821298&w=2 cve-icon cve-icon
http://marc.info/?l=vim-dev&m=117778983714029&w=2 cve-icon cve-icon
http://osvdb.org/36250 cve-icon cve-icon
http://secunia.com/advisories/25024 cve-icon cve-icon
http://secunia.com/advisories/25159 cve-icon cve-icon
http://secunia.com/advisories/25182 cve-icon cve-icon
http://secunia.com/advisories/25255 cve-icon cve-icon
http://secunia.com/advisories/25367 cve-icon cve-icon
http://secunia.com/advisories/25432 cve-icon cve-icon
http://secunia.com/advisories/26653 cve-icon cve-icon
http://tech.groups.yahoo.com/group/vimannounce/message/178 cve-icon cve-icon
http://tech.groups.yahoo.com/group/vimdev/message/46627 cve-icon cve-icon
http://tech.groups.yahoo.com/group/vimdev/message/46645 cve-icon cve-icon
http://tech.groups.yahoo.com/group/vimdev/message/46658 cve-icon cve-icon
http://www.attrition.org/pipermail/vim/2007-August/001770.html cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1364 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:101 cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_12_sr.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0346.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/467202/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/23725 cve-icon cve-icon
http://www.securitytracker.com/id?1018035 cve-icon cve-icon
http://www.trustix.org/errata/2007/0017/ cve-icon cve-icon
http://www.ubuntu.com/usn/usn-463-1 cve-icon cve-icon
http://www.vim.org/news/news.php cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/1599 cve-icon cve-icon
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=238259 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/34012 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-2438 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9876 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-2438 cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T13:42:32.149Z

Reserved: 2007-05-01T00:00:00

Link: CVE-2007-2438

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2007-05-02T21:19:00.000

Modified: 2025-04-09T00:30:58.490

Link: CVE-2007-2438

cve-icon Redhat

Severity : Moderate

Publid Date: 2007-04-26T00:00:00Z

Links: CVE-2007-2438 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses