Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-17087

Опубликовано: 01 дек. 2017
Источник: ubuntu
Приоритет: low
CVSS2: 2.1
CVSS3: 5.5

Описание

fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

2:8.0.1453-1ubuntu1
cosmic

not-affected

2:8.0.1453-1ubuntu1
devel

not-affected

2:8.0.1453-1ubuntu1
disco

not-affected

2:8.0.1453-1ubuntu1
eoan

not-affected

2:8.0.1453-1ubuntu1
esm-infra-legacy/trusty

released

2:7.4.052-1ubuntu3.1+esm4
esm-infra-legacy/xenial

released

2:7.4.1689-3ubuntu1.5
esm-infra/bionic

not-affected

2:8.0.1453-1ubuntu1
esm-infra/focal

not-affected

2:8.0.1453-1ubuntu1

Показывать по

2.1 Low

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
почти 9 лет назад

fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.

CVSS3: 5.5
nvd
больше 8 лет назад

fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.

CVSS3: 5.5
debian
больше 8 лет назад

fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp f ...

CVSS3: 5.5
github
больше 4 лет назад

fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.

CVSS3: 5.5
fstec
почти 9 лет назад

Уязвимость компонентов fileio.c, /etc/shadow, /etc/.shadow.swp текстового редактора Vim, позволяющая нарушителю получить доступ к конфиденциальным данным

2.1 Low

CVSS2

5.5 Medium

CVSS3