Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-17087

Опубликовано: 01 дек. 2017
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 2.1
CVSS3: 5.5

Описание

fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

2:8.0.1453-1ubuntu1
cosmic

not-affected

2:8.0.1453-1ubuntu1
devel

not-affected

2:8.0.1453-1ubuntu1
disco

not-affected

2:8.0.1453-1ubuntu1
eoan

not-affected

2:8.0.1453-1ubuntu1
esm-infra-legacy/trusty

released

2:7.4.052-1ubuntu3.1+esm4
esm-infra/bionic

not-affected

2:8.0.1453-1ubuntu1
esm-infra/focal

not-affected

2:8.0.1453-1ubuntu1
esm-infra/xenial

released

2:7.4.1689-3ubuntu1.5

Показывать по

EPSS

Процентиль: 37%
0.00161
Низкий

2.1 Low

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
больше 8 лет назад

fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.

CVSS3: 5.5
nvd
около 8 лет назад

fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.

CVSS3: 5.5
debian
около 8 лет назад

fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp f ...

CVSS3: 5.5
github
больше 3 лет назад

fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.

CVSS3: 5.5
fstec
больше 8 лет назад

Уязвимость компонентов fileio.c, /etc/shadow, /etc/.shadow.swp текстового редактора Vim, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 37%
0.00161
Низкий

2.1 Low

CVSS2

5.5 Medium

CVSS3