CVE-2009-0316
published 2009-01-28CVE-2009-0316: Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan…
PriorityP425medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
2.84%
85.2th percentile
Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983), as demonstrated by an erroneous search path for plugin/bike.vim in bicyclerepair.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | vim | < vim 2:7.2.025-2 (bookworm) | vim 2:7.2.025-2 (bookworm) |
| vim | vim | <= 7.2 | — |
| vim | vim | — | — |
| vim | vim | — | — |
| vim | vim | — | — |
| vim | vim | — | — |
| vim | vim | — | — |
| vim | vim | — | — |
| vim | vim | — | — |
| vim | vim | — | — |
| vim | vim | — | — |
| vim | vim | — | — |
| vim | vim | — | — |
| vim | vim | — | — |
| vim | vim | — | — |
| vim | vim | — | — |
| vim | vim | — | — |
| vim | vim | — | — |
| vim | vim | — | — |
| vim | vim | — | — |
| vim | vim | — | — |
| vim | vim | — | — |
| vim | vim | >= 0 < 2:7.2.025-2 | 2:7.2.025-2 |
| vim | vim | >= 0 < 2:7.2.025-2 | 2:7.2.025-2 |
| vim | vim | >= 0 < 2:7.2.025-2 | 2:7.2.025-2 |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9LOW
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x433-429v-9473: Untrusted search path vulnerability in src/if_python
ghsa_unreviewed·2022-05-02·CVSS 6.9
CVE-2009-0316 [MEDIUM] GHSA-x433-429v-9473: Untrusted search path vulnerability in src/if_python
Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983), as demonstrated by an erroneous search path for plugin/bike.vim in bicyclerepair.
OSV
CVE-2009-0316: Untrusted search path vulnerability in src/if_python
osv·2009-01-28·CVSS 6.9
CVE-2009-0316 [MEDIUM] CVE-2009-0316: Untrusted search path vulnerability in src/if_python
Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983), as demonstrated by an erroneous search path for plugin/bike.vim in bicyclerepair.
Debian
CVE-2009-0316: vim - Untrusted search path vulnerability in src/if_python.c in the Python interface i...
vendor_debian·2009·CVSS 6.9
CVE-2009-0316 [MEDIUM] CVE-2009-0316: vim - Untrusted search path vulnerability in src/if_python.c in the Python interface i...
Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983), as demonstrated by an erroneous search path for plugin/bike.vim in bicyclerepair.
Scope: local
bookworm: resolved (fixed in 2:7.2.025-2)
bullseye: resolved (fixed in 2:7.2.025-2)
forky: resolved (fixed in 2:7.2.025-2)
sid: resolved (fixed in 2:7.2.025-2)
trixie: resolved (fixed in 2:7.2.025-2)
Red Hat
vim: untrusted python modules search path
vendor_redhat·2008-08-06·CVSS 6.9
CVE-2009-0316 [MEDIUM] vim: untrusted python modules search path
vim: untrusted python modules search path
Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983), as demonstrated by an erroneous search path for plugin/bike.vim in bicyclerepair.
Statement: This issue did not affect vim as shipped in Red Hat Enterprise Linux 3 and 4. This issue is not planned to be fixed in vim packages in Red Hat Enterprise Linux 5.
Package: vim (Red Hat Enterprise Linux 4) - Not affected
Package: vim (Red Hat Enterprise Linux 5) - Will not fix
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=484305http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=493937http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlhttp://support.apple.com/kb/HT4077http://www.mandriva.com/security/advisories?name=MDVSA-2009:047http://www.nabble.com/Bug-484305%3A-bicyclerepair%3A-bike.vim-imports-untrusted-python-files-from-cwd-td18848099.htmlhttp://www.openwall.com/lists/oss-security/2009/01/26/2http://www.securityfocus.com/bid/33447https://bugzilla.redhat.com/show_bug.cgi?id=481565https://exchange.xforce.ibmcloud.com/vulnerabilities/48275https://svn.pardus.org.tr/pardus/2008/applications/editors/vim/files/official/7.2.045http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=484305http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=493937http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlhttp://support.apple.com/kb/HT4077http://www.mandriva.com/security/advisories?name=MDVSA-2009:047http://www.nabble.com/Bug-484305%3A-bicyclerepair%3A-bike.vim-imports-untrusted-python-files-from-cwd-td18848099.htmlhttp://www.openwall.com/lists/oss-security/2009/01/26/2http://www.securityfocus.com/bid/33447https://bugzilla.redhat.com/show_bug.cgi?id=481565https://exchange.xforce.ibmcloud.com/vulnerabilities/48275https://svn.pardus.org.tr/pardus/2008/applications/editors/vim/files/official/7.2.045
2009-01-28
Published