Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5x93-92vm-jw5m

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.

getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.

Ссылки

EPSS

Процентиль: 97%
0.19111
Средний

8.6 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 7 лет назад

getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.

CVSS3: 5.3
redhat
около 7 лет назад

getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.

CVSS3: 8.6
nvd
около 7 лет назад

getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.

CVSS3: 8.6
msrc
почти 6 лет назад

Описание отсутствует

CVSS3: 8.6
debian
около 7 лет назад

getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote ...

EPSS

Процентиль: 97%
0.19111
Средний

8.6 High

CVSS3

Дефекты

CWE-78