Advisories Blog | G5 Cyber Security

Debian Linux Security Advisory 1364-2

Debian Security Advisory 1364-2 – Several vulnerabilities have been discovered in the vim editor. Ulf Harnhammar discovered that a format string flaw in helptags_one() from src/ex_cmds.c (triggered through the “helptags” command) can lead to the execution of arbitrary code. Editors often provide a way to embed editor configuration commands (aka modelines) which are executed once a file is opened. Harmful commands are filtered by a sandbox mechanism. It was discovered that function calls to writefile(), feedkeys() and system() were not filtered, allowing shell command execution with a carefully crafted file opened in vim. This updated advisory repairs issues with missing files in the packages for the oldstable distribution (sarge) for the alpha, mips, and mipsel architectures.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/59464/dsa-1364-2.txt

Source: https://packetstormsecurity.com/files/59464/Debian-Linux-Security-Advisory-1364-2.html

Exit mobile version