CVE-2005-2368OS Command Injection in VIM

Severity
9.3CRITICALNVD
EPSS
1.5%
top 18.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 26
Latest updateMay 1

Description

vim 6.3 before 6.3.082, with modelines enabled, allows external user-assisted attackers to execute arbitrary commands via shell metacharacters in the (1) glob or (2) expand commands of a foldexpr expression for calculating fold levels.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages3 packages

debiandebian/vim< vim 1:6.3-085+1 (bookworm)
Debianvim/vim< 1:6.3-085+1+3
NVDvim_development_group/vim6 versions+5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-w427-f3fp-6x6x: vim 62022-05-01
OSV
CVE-2005-2368: vim 62005-07-26

📋Vendor Advisories

2
Red Hat
security flaw2005-07-25
Debian
CVE-2005-2368: vim - vim 6.3 before 6.3.082, with modelines enabled, allows external user-assisted at...2005

💬Community

1
Bugzilla
CVE-2005-2368 security flaw2018-08-16