Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-1000382

Опубликовано: 31 окт. 2017
Источник: debian
EPSS Низкий

Описание

VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the vi binary.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
vimunfixedpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2017/10/31/15

  • Cf. https://www.openwall.com/lists/oss-security/2017/11/01/4

  • vim creates the .swp file according to the permissions of the file being

  • edited, admitely ignoring the umask, so in the reporters case the .swp

  • file is readable by others. But that seem to be the intended behaviour.

EPSS

Процентиль: 31%
0.00117
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the vi binary.

CVSS3: 5.5
redhat
больше 8 лет назад

VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the vi binary.

CVSS3: 5.5
nvd
больше 8 лет назад

VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the vi binary.

CVSS3: 5.5
github
больше 3 лет назад

VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the vi binary.

EPSS

Процентиль: 31%
0.00117
Низкий