Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-3294

Опубликовано: 24 июл. 2008
Источник: nvd
CVSS2: 3.7
EPSS Низкий

Описание

src/configure.in in Vim 5.0 through 7.1, when used for a build with Python support, does not ensure that the Makefile-conf temporary file has the intended ownership and permissions, which allows local users to execute arbitrary code by modifying this file during a time window, or by creating it ahead of time with permissions that prevent its modification by configure.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:vim:vim:5.0:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:5.1:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:5.2:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:5.3:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:5.4:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:5.5:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:5.6:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:5.7:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:5.8:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:6.0:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:6.1:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:6.2:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:6.3:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:6.4:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:7.0:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:7.1:*:*:*:*:*:*:*

EPSS

Процентиль: 34%
0.00132
Низкий

3.7 Low

CVSS2

Дефекты

CWE-94

Связанные уязвимости

ubuntu
около 17 лет назад

src/configure.in in Vim 5.0 through 7.1, when used for a build with Python support, does not ensure that the Makefile-conf temporary file has the intended ownership and permissions, which allows local users to execute arbitrary code by modifying this file during a time window, or by creating it ahead of time with permissions that prevent its modification by configure.

redhat
около 17 лет назад

src/configure.in in Vim 5.0 through 7.1, when used for a build with Python support, does not ensure that the Makefile-conf temporary file has the intended ownership and permissions, which allows local users to execute arbitrary code by modifying this file during a time window, or by creating it ahead of time with permissions that prevent its modification by configure.

debian
около 17 лет назад

src/configure.in in Vim 5.0 through 7.1, when used for a build with Py ...

github
больше 3 лет назад

src/configure.in in Vim 5.0 through 7.1, when used for a build with Python support, does not ensure that the Makefile-conf temporary file has the intended ownership and permissions, which allows local users to execute arbitrary code by modifying this file during a time window, or by creating it ahead of time with permissions that prevent its modification by configure.

EPSS

Процентиль: 34%
0.00132
Низкий

3.7 Low

CVSS2

Дефекты

CWE-94