Описание
A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.
Отчет
Important: This Vimscript injection flaw in netrw allows arbitrary code execution with user privileges. Exploitation requires a local attacker to place a specially crafted filename in a directory and a victim to browse that directory with netrw and interact with the malicious entry. This directly impacts the confidentiality, integrity, and availability of the user's data and environment.
Меры по смягчению последствий
To mitigate this issue, users should avoid browsing untrusted directories or interacting with files from untrusted sources using Vim's netrw plugin. Exercise caution when opening directories that may contain maliciously crafted filenames.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | vim | Under investigation | ||
| Red Hat Enterprise Linux 6 | vim | Under investigation | ||
| Red Hat Enterprise Linux 7 | vim | Under investigation | ||
| Red Hat Enterprise Linux 8 | vim | Under investigation | ||
| Red Hat Enterprise Linux 9 | vim | Under investigation | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Under investigation | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Under investigation |
Показывать по
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.
A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.
A flaw was found in Vim's netrw plugin. A crafted filename containing ...
EPSS
7.8 High
CVSS3