Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-3076

Опубликовано: 21 фев. 2009
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 9.3

Описание

The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames used by the execute and system functions within the (1) mz and (2) mc commands, as demonstrated by the netrw.v2 and netrw.v3 test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712.

РелизСтатусПримечание
dapper

not-affected

1:6.4-006+2ubuntu6.2
devel

not-affected

2:7.2.079-1ubuntu3
gutsy

not-affected

1:7.1-056+2ubuntu2.1
hardy

not-affected

1:7.1-138+1ubuntu3.1
intrepid

not-affected

1:7.1.314-3ubuntu3.1
upstream

needs-triage

Показывать по

Ссылки на источники

EPSS

Процентиль: 93%
0.10902
Средний

9.3 Critical

CVSS2

Связанные уязвимости

redhat
около 17 лет назад

The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames used by the execute and system functions within the (1) mz and (2) mc commands, as demonstrated by the netrw.v2 and netrw.v3 test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712.

nvd
больше 16 лет назад

The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames used by the execute and system functions within the (1) mz and (2) mc commands, as demonstrated by the netrw.v2 and netrw.v3 test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712.

debian
больше 16 лет назад

The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted ...

github
больше 3 лет назад

The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames used by the execute and system functions within the (1) mz and (2) mc commands, as demonstrated by the netrw.v2 and netrw.v3 test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712.

EPSS

Процентиль: 93%
0.10902
Средний

9.3 Critical

CVSS2