Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-3076

Опубликовано: 21 фев. 2009
Источник: ubuntu
Приоритет: medium
CVSS2: 9.3

Описание

The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames used by the execute and system functions within the (1) mz and (2) mc commands, as demonstrated by the netrw.v2 and netrw.v3 test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712.

РелизСтатусПримечание
dapper

not-affected

1:6.4-006+2ubuntu6.2
devel

not-affected

2:7.2.079-1ubuntu3
gutsy

not-affected

1:7.1-056+2ubuntu2.1
hardy

not-affected

1:7.1-138+1ubuntu3.1
intrepid

not-affected

1:7.1.314-3ubuntu3.1
upstream

needs-triage

Показывать по

Ссылки на источники

9.3 Critical

CVSS2

Связанные уязвимости

redhat
больше 17 лет назад

The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames used by the execute and system functions within the (1) mz and (2) mc commands, as demonstrated by the netrw.v2 and netrw.v3 test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712.

nvd
почти 17 лет назад

The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames used by the execute and system functions within the (1) mz and (2) mc commands, as demonstrated by the netrw.v2 and netrw.v3 test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712.

debian
почти 17 лет назад

The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted ...

github
почти 4 года назад

The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames used by the execute and system functions within the (1) mz and (2) mc commands, as demonstrated by the netrw.v2 and netrw.v3 test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712.

9.3 Critical

CVSS2