USN-4582-1
Dashboard / Vulnerabilities / USN-4582-1
USN-4582-1
Summary: vim vulnerabilities
Details: It was discovered that Vim incorrectly handled permissions on the .swp file. A local attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-17087) It was discovered that Vim incorrectly handled restricted mode. A local attacker could possibly use this issue to bypass restricted mode and execute arbitrary commands. Note: This update only makes executing shell commands more difficult. Restricted mode should not be considered a complete security measure. (CVE-2019-20807)
References: https://ubuntu.com/security/notices/USN-4582-1, https://ubuntu.com/security/CVE-2017-17087, https://ubuntu.com/security/CVE-2019-20807
Affected packages
Package
Name: vim
Purl: pkg:deb/ubuntu/vim@2:7.4.1689-3ubuntu1.5?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
