CVE-2005-0069VIM vulnerability

7 documents7 sources
Severity
4.6MEDIUMNVD
EPSS
0.1%
top 76.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13
Latest updateMay 1

Description

The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages3 packages

debiandebian/vim< vim 1:6.3-058+1 (bookworm)
Debianvim/vim< 1:6.3-058+1+3
NVDvim_development_group/vim4 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8p47-83g5-grhh: The (1) tcltags or (2) vimspell2022-05-01
OSV
CVE-2005-0069: The (1) tcltags or (2) vimspell2005-01-13

📋Vendor Advisories

3
Ubuntu
vim vulnerabilities2005-01-19
Red Hat
security flaw2005-01-09
Debian
CVE-2005-0069: vim - The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overw...2005

💬Community

1
Bugzilla
CVE-2005-0069 security flaw2018-08-16