VulnerabilityModified
CVE-2002-1377
vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which are not sandboxed but may be executed when vim is used to edit a malicious file, as demonstrated using mutt.
MEDIUM 4.6EPSS 0.47%
Does this matter?
Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.
Description
vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which are not sandboxed but may be executed when vim is used to edit a malicious file, as demonstrated using mutt.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.47% probability · 40th percentile
- CISA KEV
- Not listed
- Affected
- vim development group/vim
- Source
- cve@mitre.org
References
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000812
- http://lists.grok.org.uk/pipermail/full-disclosure/2002-December/002948.html
- http://marc.info/?l=bugtraq&m=108077992208690&w=2
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/55700
- http://www.guninski.com/vim1.htmlPatch, Vendor Advisory
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:012
- http://www.redhat.com/support/errata/RHSA-2002-297.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2002-302.html
- http://www.securityfocus.com/bid/6384
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10835
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000812
- http://lists.grok.org.uk/pipermail/full-disclosure/2002-December/002948.html
- http://marc.info/?l=bugtraq&m=108077992208690&w=2
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/55700
- http://www.guninski.com/vim1.htmlPatch, Vendor Advisory
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:012
- http://www.redhat.com/support/errata/RHSA-2002-297.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2002-302.html
- http://www.securityfocus.com/bid/6384
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10835
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.