CVE-2002-1377
Last modified
CVE-2002-1377 is a vulnerability of currently unknown severity. vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which are not sandboxed but may be executed when vim is used to edit a malicious file, as demonstrated using mutt.. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which are not sandboxed but may be executed when vim is used to edit a malicious file, as demonstrated using mutt.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vim Development Group | Vim | 5.0 |
| Vim Development Group | Vim | 5.1 |
| Vim Development Group | Vim | 5.2 |
| Vim Development Group | Vim | 5.3 |
| Vim Development Group | Vim | 5.4 |
| Vim Development Group | Vim | 5.5 |
| Vim Development Group | Vim | 5.6 |
| Vim Development Group | Vim | 5.7 |
| Vim Development Group | Vim | 5.8 |
| Vim Development Group | Vim | 6.0 |
| Vim Development Group | Vim | 6.1 |
References
- http://www.guninski.com/vim1.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2002-297.htmlPatch, Vendor Advisory
- http://www.guninski.com/vim1.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2002-297.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-1377?
How severe is CVE-2002-1377?
How do I fix CVE-2002-1377?
Are you affected by CVE-2002-1377?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
