Описание
An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c
A flaw was found in Vim. A local attacker could exploit a vulnerability in the vms_fixfilename() function, allowing them to execute arbitrary code on the system. This could lead to a complete compromise of the affected system.
Отчет
Red Hat Enterprise Linux and Fedora build Vim against the POSIX/Linux platform layer (os_unix.c). The vulnerable function, vms_fixfilename(), is defined in os_vms.c, which provides OpenVMS-specific support and is never compiled into Red Hat's or Fedora's Vim packages. As a result, none of Red Hat's shipped Vim builds contain the affected code path.
Меры по смягчению последствий
No mitigation is required. Red Hat does not ship any product containing the vulnerable code path - the affected function is confined to Vim's OpenVMS platform support, which is not included in Red Hat Enterprise Linux or Fedora builds.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | vim | Not affected | ||
| Red Hat Enterprise Linux 6 | vim | Not affected | ||
| Red Hat Enterprise Linux 7 | vim | Not affected | ||
| Red Hat Enterprise Linux 8 | vim | Not affected | ||
| Red Hat Enterprise Linux 9 | vim | Not affected | ||
| Red Hat Hardened Images | vim | Not affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c
An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c
An issue in Vim Project v9.2.0389 and earlier allows a local attacker ...
An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c
EPSS
7.8 High
CVSS3