CVE-2007-2953
published 2007-07-31CVE-2007-2953: Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted remote attackers to…
PriorityP432medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.18%
89.7th percentile
Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a help-tags tag in a help file, related to the helptags command.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | vim | < vim 1:7.1-056+1 (bookworm) | vim 1:7.1-056+1 (bookworm) |
| vim | vim | >= 0 < 1:7.1-056+1 | 1:7.1-056+1 |
| vim | vim | >= 0 < 1:7.1-056+1 | 1:7.1-056+1 |
| vim | vim | >= 0 < 1:7.1-056+1 | 1:7.1-056+1 |
| vim | vim | >= 0 < 1:7.1-056+1 | 1:7.1-056+1 |
| vim_development_group | vim | <= 6.4 | — |
| vim_development_group | vim | — | — |
| vim_development_group | vim | — | — |
| vim_development_group | vim | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ggw5-mghh-pg96: Format string vulnerability in the helptags_one function in src/ex_cmds
ghsa_unreviewed·2022-05-03
CVE-2007-2953 [MEDIUM] GHSA-ggw5-mghh-pg96: Format string vulnerability in the helptags_one function in src/ex_cmds
Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a help-tags tag in a help file, related to the helptags command.
OSV
CVE-2007-2953: Format string vulnerability in the helptags_one function in src/ex_cmds
osv·2007-07-31·CVSS 6.8
CVE-2007-2953 [MEDIUM] CVE-2007-2953: Format string vulnerability in the helptags_one function in src/ex_cmds
Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a help-tags tag in a help file, related to the helptags command.
Ubuntu
vim vulnerability
vendor_ubuntu·2007-08-28
CVE-2007-2953 vim vulnerability
Title: vim vulnerability
Summary: vim vulnerability
Ulf Harnhammar discovered that vim does not properly sanitise the
"helptags_one()" function when running the "helptags" command.
By tricking a user into running a crafted help file, a remote attacker
could execute arbitrary code with the user's privileges.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
vim format string flaw
vendor_redhat·2007-07-25·CVSS 6.8
CVE-2007-2953 [MEDIUM] vim format string flaw
vim format string flaw
Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a help-tags tag in a help file, related to the helptags command.
Statement: Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=248542
The Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here: https://access.redhat.com/security/updates/classification/
Debian
CVE-2007-2953: vim - Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim...
vendor_debian·2007·CVSS 6.8
CVE-2007-2953 [MEDIUM] CVE-2007-2953: vim - Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim...
Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a help-tags tag in a help file, related to the helptags command.
Scope: local
bookworm: resolved (fixed in 1:7.1-056+1)
bullseye: resolved (fixed in 1:7.1-056+1)
forky: resolved (fixed in 1:7.1-056+1)
sid: resolved (fixed in 1:7.1-056+1)
trixie: resolved (fixed in 1:7.1-056+1)
No detection rules found.
No public exploits indexed.
ftp://ftp.vim.org/pub/vim/patches/7.1/7.1.039http://secunia.com/advisories/25941http://secunia.com/advisories/26285http://secunia.com/advisories/26522http://secunia.com/advisories/26594http://secunia.com/advisories/26653http://secunia.com/advisories/26674http://secunia.com/advisories/26822http://secunia.com/advisories/32858http://secunia.com/advisories/33410http://secunia.com/secunia_research/2007-66/advisory/http://support.avaya.com/elmodocs2/security/ASA-2009-001.htmhttp://www.attrition.org/pipermail/vim/2007-August/001770.htmlhttp://www.debian.org/security/2007/dsa-1364http://www.mandriva.com/security/advisories?name=MDKSA-2007:168http://www.mandriva.com/security/advisories?name=MDVSA-2008:236http://www.novell.com/linux/security/advisories/2007_18_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0580.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0617.htmlhttp://www.securityfocus.com/archive/1/475076/100/100/threadedhttp://www.securityfocus.com/archive/1/502322/100/0/threadedhttp://www.securityfocus.com/bid/25095http://www.trustix.org/errata/2007/0026/http://www.ubuntu.com/usn/usn-505-1http://www.vmware.com/security/advisories/VMSA-2009-0004.htmlhttp://www.vupen.com/english/advisories/2007/2687http://www.vupen.com/english/advisories/2009/0033http://www.vupen.com/english/advisories/2009/0904https://exchange.xforce.ibmcloud.com/vulnerabilities/35655https://issues.rpath.com/browse/RPL-1595https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11549https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6463ftp://ftp.vim.org/pub/vim/patches/7.1/7.1.039http://secunia.com/advisories/25941http://secunia.com/advisories/26285http://secunia.com/advisories/26522http://secunia.com/advisories/26594http://secunia.com/advisories/26653http://secunia.com/advisories/26674http://secunia.com/advisories/26822http://secunia.com/advisories/32858http://secunia.com/advisories/33410http://secunia.com/secunia_research/2007-66/advisory/http://support.avaya.com/elmodocs2/security/ASA-2009-001.htmhttp://www.attrition.org/pipermail/vim/2007-August/001770.htmlhttp://www.debian.org/security/2007/dsa-1364http://www.mandriva.com/security/advisories?name=MDKSA-2007:168http://www.mandriva.com/security/advisories?name=MDVSA-2008:236http://www.novell.com/linux/security/advisories/2007_18_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0580.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0617.htmlhttp://www.securityfocus.com/archive/1/475076/100/100/threadedhttp://www.securityfocus.com/archive/1/502322/100/0/threadedhttp://www.securityfocus.com/bid/25095http://www.trustix.org/errata/2007/0026/http://www.ubuntu.com/usn/usn-505-1http://www.vmware.com/security/advisories/VMSA-2009-0004.htmlhttp://www.vupen.com/english/advisories/2007/2687http://www.vupen.com/english/advisories/2009/0033http://www.vupen.com/english/advisories/2009/0904https://exchange.xforce.ibmcloud.com/vulnerabilities/35655https://issues.rpath.com/browse/RPL-1595https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11549https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6463
2007-07-31
Published