CVE-2008-6235
published 2009-02-21CVE-2008-6235: The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a filename used by the…
PriorityP346critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.99%
85.8th percentile
The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a filename used by the (1) "D" (delete) command or (2) b:netrw_curdir variable, as demonstrated using the netrw.v4 and netrw.v5 test cases.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | vim | < vim 2:7.2.148-1 (bookworm) | vim 2:7.2.148-1 (bookworm) |
| vim | vim | — | — |
| vim | vim | — | — |
| vim | vim | >= 0 < 2:7.2.148-1 | 2:7.2.148-1 |
| vim | vim | >= 0 < 2:7.2.148-1 | 2:7.2.148-1 |
| vim | vim | >= 0 < 2:7.2.148-1 | 2:7.2.148-1 |
| vim | vim | >= 0 < 2:7.2.148-1 | 2:7.2.148-1 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3LOW
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
plugin: lack of sanitization throughout netrw.vim can lead to arbitrary code execution
vendor_redhat·2008-07-15·CVSS 9.3
CVE-2008-3076 [CRITICAL] plugin: lack of sanitization throughout netrw.vim can lead to arbitrary code execution
plugin: lack of sanitization throughout netrw.vim can lead to arbitrary code execution
The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames used by the execute and system functions within the (1) mz and (2) mc commands, as demonstrated by the netrw.v2 and netrw.v3 test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712.
Statement: Not vulnerable. This issue did not affect the versions of the Vim packages, as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and 5.
Note: This CVE is mentioned in the text of RHSA-2008:0580 as it was originally used to track multiple issues. Issues that affected Vim packages in Red Hat Enterprise Linux 5 were later assigned separat
Red Hat
plugin: lack of sanitization throughout netrw.vim can lead to arbitrary code execution
vendor_redhat·2008-07-15·CVSS 9.3
CVE-2008-6235 [CRITICAL] plugin: lack of sanitization throughout netrw.vim can lead to arbitrary code execution
plugin: lack of sanitization throughout netrw.vim can lead to arbitrary code execution
The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a filename used by the (1) "D" (delete) command or (2) b:netrw_curdir variable, as demonstrated using the netrw.v4 and netrw.v5 test cases.
Debian
CVE-2008-6235: vim - The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers t...
vendor_debian·2008·CVSS 9.3
CVE-2008-6235 [CRITICAL] CVE-2008-6235: vim - The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers t...
The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a filename used by the (1) "D" (delete) command or (2) b:netrw_curdir variable, as demonstrated using the netrw.v4 and netrw.v5 test cases.
Scope: local
bookworm: resolved (fixed in 2:7.2.148-1)
bullseye: resolved (fixed in 2:7.2.148-1)
forky: resolved (fixed in 2:7.2.148-1)
sid: resolved (fixed in 2:7.2.148-1)
trixie: resolved (fixed in 2:7.2.148-1)
GHSA
GHSA-f7gm-2q6r-xxwv: The Netrw plugin (netrw
ghsa_unreviewed·2022-05-17
CVE-2008-6235 [HIGH] CWE-78 GHSA-f7gm-2q6r-xxwv: The Netrw plugin (netrw
The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a filename used by the (1) "D" (delete) command or (2) b:netrw_curdir variable, as demonstrated using the netrw.v4 and netrw.v5 test cases.
OSV
CVE-2008-6235: The Netrw plugin (netrw
osv·2009-02-21·CVSS 9.3
CVE-2008-6235 [CRITICAL] CVE-2008-6235: The Netrw plugin (netrw
The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a filename used by the (1) "D" (delete) command or (2) b:netrw_curdir variable, as demonstrated using the netrw.v4 and netrw.v5 test cases.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.htmlhttp://secunia.com/advisories/34418http://www.openwall.com/lists/oss-security/2008/10/16/2http://www.openwall.com/lists/oss-security/2008/10/20/2http://www.rdancer.org/vulnerablevim-netrw.htmlhttp://www.rdancer.org/vulnerablevim-netrw.v2.htmlhttp://www.rdancer.org/vulnerablevim-netrw.v5.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0580.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11247http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.htmlhttp://secunia.com/advisories/34418http://www.openwall.com/lists/oss-security/2008/10/16/2http://www.openwall.com/lists/oss-security/2008/10/20/2http://www.rdancer.org/vulnerablevim-netrw.htmlhttp://www.rdancer.org/vulnerablevim-netrw.v2.htmlhttp://www.rdancer.org/vulnerablevim-netrw.v5.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0580.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11247
2009-02-21
Published