CVE-2017-1000382Sensitive Information Exposure in VIM

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 74.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 31
Latest updateMay 17

Description

VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the vi binary.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

NVDvim/vim< 8.0.1263+1
debiandebian/vim< vim 2:8.0.1401-1 (bookworm)+1
Debianvim/vim< 2:8.0.1401-1+3

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 16.04, 18.04

🔴Vulnerability Details

4
GHSA
GHSA-fc3h-fxv9-79gq: VIM version 82022-05-17
GHSA
GHSA-fmc8-f7rh-x4p9: fileio2022-05-13
OSV
CVE-2017-17087: fileio2017-12-01
OSV
CVE-2017-1000382: VIM version 82017-10-31

📋Vendor Advisories

4
Red Hat
vim: Sets the group ownership of a .swp file to the editor's primary group2017-11-04
Red Hat
vim: Ignores umask when creating a swap file2017-10-31
Debian
CVE-2017-1000382: vim - VIM version 8.0.1187 (and other versions most likely) ignores umask when creatin...2017
Debian
CVE-2017-17087: vim - fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the...2017

💬Community

3
Bugzilla
CVE-2017-17087 vim: Sets the group ownership of a .swp file to the editor's primary group2017-12-11
Bugzilla
CVE-2017-1000382 vim: Ignores umask when creating a swap file2017-11-02
Bugzilla
CVE-2017-1000382 vim: Ignores umask when creating a swap file [fedora-all]2017-11-02