Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-3075

Опубликовано: 21 фев. 2009
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exclamation point) shell metacharacter in (1) the filename of a ZIP archive and possibly (2) the filename of the first file in a ZIP archive, which is not properly handled by zip.vim in the VIM ZIP plugin (zipPlugin.vim) v.11 through v.21, as demonstrated by the zipplugin and zipplugin.v2 test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712. NOTE: this issue has the same root cause as CVE-2008-3074. NOTE: due to the complexity of the associated disclosures and the incomplete information related to them, there may be inaccuracies in this CVE description and in external mappings to this identifier.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:vim:vim:7.0:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:7.1:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:7.1.266:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:7.1.314:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:7.2:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:7.2a.10:*:*:*:*:*:*:*
cpe:2.3:a:vim:zipplugin.vim:v.11:*:*:*:*:*:*:*
cpe:2.3:a:vim:zipplugin.vim:v.12:*:*:*:*:*:*:*
cpe:2.3:a:vim:zipplugin.vim:v.13:*:*:*:*:*:*:*
cpe:2.3:a:vim:zipplugin.vim:v.14:*:*:*:*:*:*:*
cpe:2.3:a:vim:zipplugin.vim:v.15:*:*:*:*:*:*:*
cpe:2.3:a:vim:zipplugin.vim:v.16:*:*:*:*:*:*:*
cpe:2.3:a:vim:zipplugin.vim:v.17:*:*:*:*:*:*:*
cpe:2.3:a:vim:zipplugin.vim:v.18:*:*:*:*:*:*:*
cpe:2.3:a:vim:zipplugin.vim:v.19:*:*:*:*:*:*:*
cpe:2.3:a:vim:zipplugin.vim:v.20:*:*:*:*:*:*:*
cpe:2.3:a:vim:zipplugin.vim:v.21:*:*:*:*:*:*:*

EPSS

Процентиль: 89%
0.05056
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-94

Связанные уязвимости

ubuntu
больше 16 лет назад

The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exclamation point) shell metacharacter in (1) the filename of a ZIP archive and possibly (2) the filename of the first file in a ZIP archive, which is not properly handled by zip.vim in the VIM ZIP plugin (zipPlugin.vim) v.11 through v.21, as demonstrated by the zipplugin and zipplugin.v2 test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712. NOTE: this issue has the same root cause as CVE-2008-3074. NOTE: due to the complexity of the associated disclosures and the incomplete information related to them, there may be inaccuracies in this CVE description and in external mappings to this identifier.

redhat
почти 17 лет назад

The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exclamation point) shell metacharacter in (1) the filename of a ZIP archive and possibly (2) the filename of the first file in a ZIP archive, which is not properly handled by zip.vim in the VIM ZIP plugin (zipPlugin.vim) v.11 through v.21, as demonstrated by the zipplugin and zipplugin.v2 test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712. NOTE: this issue has the same root cause as CVE-2008-3074. NOTE: due to the complexity of the associated disclosures and the incomplete information related to them, there may be inaccuracies in this CVE description and in external mappings to this identifier.

debian
больше 16 лет назад

The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, al ...

github
около 3 лет назад

The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exclamation point) shell metacharacter in (1) the filename of a ZIP archive and possibly (2) the filename of the first file in a ZIP archive, which is not properly handled by zip.vim in the VIM ZIP plugin (zipPlugin.vim) v.11 through v.21, as demonstrated by the zipplugin and zipplugin.v2 test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712. NOTE: this issue has the same root cause as CVE-2008-3074. NOTE: due to the complexity of the associated disclosures and the incomplete information related to them, there may be inaccuracies in this CVE description and in external mappings to this identifier.

oracle-oval
больше 16 лет назад

ELSA-2008-0580: vim security update (MODERATE)

EPSS

Процентиль: 89%
0.05056
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-94