Openwall Project   /home  Owl  JtR  Pro  crypt  pam_passwdqc  tcb  phpass  scanlogd  popa3d  msulogin  /  Linux  BIND  /  advisories  presentations  /  services  donations  /  wordlists  passwords  /  news  community  lists  wiki  CVSweb  mirrors  signatures
bringing security into open environments
 
Password Recovery Resources on the Net
[<prev] [next>] [<thread-prev] [month] [year] [list]
Date: Tue, 15 Jul 2008 11:00:27 +0200
From: Tomas Hoger <thoger@...hat.com>
To: oss-security@...ts.openwall.com
Cc: coley@...us.mitre.org, Jamie Strandboge <jamie@...onical.com>
Subject: Re: CVE Id request: vim

On Mon, 16 Jun 2008 16:47:07 -0400 (EDT) "Steven M. Christey"
<coley@...us.mitre.org> wrote:

> In a perfect world, we'd know which Vim scripts were vulnerable in
> which version, but I don't see an easy way of determining that.  So,
> only one CVE is being assigned for them, pending any additional
> details.

Let's push the world a bit towards "perfect" state ;)

- zip.vim and tar.vim (omitted in the CVE description) only seem to be
shipped with vim as of vim 7.0.  6.x versions of vim do not have them
and can not be used to browse .zip/.tar archives.  Affected in versions
used in 7.0 and 7.1.  I don't see them in 6.4 tarball, so no sure why
advisory states 6.4 is not affected.  6.3 and 6.0 were verified to be
unaffected.

- netrw seems to be used as directory explorer as of vim 7.0.  However,
netrw test case triggers similar problem in explorer.vim plugin used in
vim 6.x versions.  So netrw test reports vulnerable for multiple
versions back to 6.0 (tested on 7.1, 7.0, 6.3 and 6.0), even though
different plugins are affected on 7.x and 6.x.

- All other tests affect vim versions at least back to 6.0 (tested on
versions listed above).

> ======================================================
> Name: CVE-2008-2712
> Status: Candidate
> URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2712
> Reference: BUGTRAQ:20080613 Collection of Vulnerabilities in Fully
> Patched Vim 7.1 Reference:
> URL:http://www.securityfocus.com/archive/1/archive/1/493352/100/0/threaded
> Reference: BUGTRAQ:20080614 Re: Collection of Vulnerabilities in
> Fully Patched Vim 7.1 Reference:
> URL:http://www.securityfocus.com/archive/1/archive/1/493353/100/0/threaded
> Reference: MISC:http://www.rdancer.org/vulnerablevim.html Reference:
> MLIST:[oss-security] CVE Id request: vim Reference:
> URL:http://www.openwall.com/lists/oss-security/2008/06/16/2
> 
> Vim 7.1.314, 6.4, and other versions allows user-assisted remote
> attackers to execute arbitrary commands via Vim scripts that do not
> properly sanitize inputs before invoking the execute or system
> functions, as demonstrated using (1) filetype.vim, (2) zipplugin, (3)
> xpm.vim, (4) gzip_vim, and (5) netrw.

-- 
Tomas Hoger / Red Hat Security Response Team

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux