CVE-2017-17087
published 2017-12-01CVE-2017-17087: fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.36%
27.8th percentile
fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | vim | < vim 2:8.0.1401-1 (bookworm) | vim 2:8.0.1401-1 (bookworm) |
| vim | vim | < 8.0.1263 | 8.0.1263 |
| vim | vim | >= 0 < 2:8.0.1401-1 | 2:8.0.1401-1 |
| vim | vim | >= 0 < 2:8.0.1401-1 | 2:8.0.1401-1 |
| vim | vim | >= 0 < 2:8.0.1401-1 | 2:8.0.1401-1 |
| vim | vim | >= 0 < 2:8.0.1401-1 | 2:8.0.1401-1 |
| vim | vim | >= 0 < 2:7.4.1689-3ubuntu1.5 | 2:7.4.1689-3ubuntu1.5 |
| vim | vim | >= 0 < 2:8.0.1453-1ubuntu1.7 | 2:8.0.1453-1ubuntu1.7 |
| vim | vim | >= 0 < 2:8.0.1453-1ubuntu1.4 | 2:8.0.1453-1ubuntu1.4 |
| vim | vim | >= 0 < 2:8.1.2269-1ubuntu5.4 | 2:8.1.2269-1ubuntu5.4 |
| vim | vim | >= 0 < 2:7.4.052-1ubuntu3.1+esm4 | 2:7.4.052-1ubuntu3.1+esm4 |
| vim | vim | >= 0 < 2:7.4.1689-3ubuntu1.5+esm3 | 2:7.4.1689-3ubuntu1.5+esm3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Vim vulnerabilities
vendor_ubuntu·2021-11-15·CVSS 5.5
CVE-2021-3928 [MEDIUM] Vim vulnerabilities
Title: Vim vulnerabilities
Summary: Several security issues were fixed in Vim.
It was discovered that Vim incorrectly handled permissions on the .swp
file. A local attacker could possibly use this issue to obtain sensitive
information. This issue only affected Ubuntu 14.04 ESM. (CVE-2017-17087)
It was discovered that Vim incorrectly handled restricted mode. A local
attacker could possibly use this issue to bypass restricted mode and
execute arbitrary commands. Note: This update only makes executing shell
commands more difficult. Restricted mode should not be considered a
complete security measure. This issue only affected Ubuntu 14.04 ESM.
(CVE-2019-20807)
Brian Carpenter discovered that vim incorrectly handled memory
when opening certain files. If a user was tricked into opening
a spe
Ubuntu
Vim vulnerabilities
vendor_ubuntu·2020-10-14·CVSS 5.5
CVE-2019-20807 [MEDIUM] Vim vulnerabilities
Title: Vim vulnerabilities
Summary: Several security issues were fixed in Vim.
It was discovered that Vim incorrectly handled permissions on the .swp
file. A local attacker could possibly use this issue to obtain sensitive
information. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-17087)
It was discovered that Vim incorrectly handled restricted mode. A local
attacker could possibly use this issue to bypass restricted mode and
execute arbitrary commands. Note: This update only makes executing shell
commands more difficult. Restricted mode should not be considered a
complete security measure. (CVE-2019-20807)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
vim: Sets the group ownership of a .swp file to the editor's primary group
vendor_redhat·2017-11-04·CVSS 5.5
CVE-2017-17087 [MEDIUM] CWE-266 vim: Sets the group ownership of a .swp file to the editor's primary group
vim: Sets the group ownership of a .swp file to the editor's primary group
fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.
It was found that the swap file created by vim when opening a file was using the user's primary group instead of the file's group. An attacker belonging to the victim's primary group could use this flaw to read the vim swap file.
Statement: Red Hat Product Security has rated thi
Debian
CVE-2017-17087: vim - fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the...
vendor_debian·2017·CVSS 5.5
CVE-2017-17087 [MEDIUM] CVE-2017-17087: vim - fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the...
fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.
Scope: local
bookworm: resolved (fixed in 2:8.0.1401-1)
bullseye: resolved (fixed in 2:8.0.1401-1)
forky: resolved (fixed in 2:8.0.1401-1)
sid: resolved (fixed in 2:8.0.1401-1)
trixie: resolved (fixed in 2:8.0.1401-1)
GHSA
GHSA-fmc8-f7rh-x4p9: fileio
ghsa_unreviewed·2022-05-13·CVSS 5.5
CVE-2017-17087 [MEDIUM] CWE-668 GHSA-fmc8-f7rh-x4p9: fileio
fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.
OSV
vim vulnerabilities
osv·2021-11-15·CVSS 5.5
CVE-2017-17087 [MEDIUM] vim vulnerabilities
vim vulnerabilities
It was discovered that Vim incorrectly handled permissions on the .swp
file. A local attacker could possibly use this issue to obtain sensitive
information. This issue only affected Ubuntu 14.04 ESM. (CVE-2017-17087)
It was discovered that Vim incorrectly handled restricted mode. A local
attacker could possibly use this issue to bypass restricted mode and
execute arbitrary commands. Note: This update only makes executing shell
commands more difficult. Restricted mode should not be considered a
complete security measure. This issue only affected Ubuntu 14.04 ESM.
(CVE-2019-20807)
Brian Carpenter discovered that vim incorrectly handled memory
when opening certain files. If a user was tricked into opening
a specially crafted file, a remote attacker could crash the
appli
OSV
vim vulnerabilities
osv·2020-10-14·CVSS 5.5
CVE-2017-17087 [MEDIUM] vim vulnerabilities
vim vulnerabilities
It was discovered that Vim incorrectly handled permissions on the .swp
file. A local attacker could possibly use this issue to obtain sensitive
information. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-17087)
It was discovered that Vim incorrectly handled restricted mode. A local
attacker could possibly use this issue to bypass restricted mode and
execute arbitrary commands. Note: This update only makes executing shell
commands more difficult. Restricted mode should not be considered a
complete security measure. (CVE-2019-20807)
OSV
CVE-2017-17087: fileio
osv·2017-12-01·CVSS 5.5
CVE-2017-17087 [MEDIUM] CVE-2017-17087: fileio
fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-17087 vim: Sets the group ownership of a .swp file to the editor's primary group
bugzilla·2017-12-11·CVSS 5.5
CVE-2017-17087 [MEDIUM] CVE-2017-17087 vim: Sets the group ownership of a .swp file to the editor's primary group
CVE-2017-17087 vim: Sets the group ownership of a .swp file to the editor's primary group
fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.
References:
http://openwall.com/lists/oss-security/2017/11/27/2
https://groups.google.com/forum/#!msg/vim_dev/sRT9BtjLWMk/BRtSXNU4BwAJ
Upstream patch:
https://github.com/vim/vim/commit/5a73e0ca54c77e067c3b12ea6f35e3e8681e8cf8
Discussion:
Created vim tracking b
Bugzilla
CVE-2017-17087 vim: Sets the group ownership of a .swp file to the editor's primary group [fedora-26]
bugzilla·2017-12-11·CVSS 5.5
CVE-2017-17087 [MEDIUM] CVE-2017-17087 vim: Sets the group ownership of a .swp file to the editor's primary group [fedora-26]
CVE-2017-17087 vim: Sets the group ownership of a .swp file to the editor's primary group [fedora-26]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-26.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the followin
Checkpoint
2nd November – Threat Intelligence Bulletin
blogs_checkpoint·2020-11-02
CVE-2020-17087 2nd November – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 2nd November – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 2nd November, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
CISA, FBI and HHS have released a warning against an increase in Ryuk ransomware attacks on US hospitals. Check Point Research have shown that indeed, healthcare is currently the most targeted industry in the US, with a 71% increase in attacks compared to last month. Other regions have experienced an increase of 30%.
C
http://openwall.com/lists/oss-security/2017/11/27/2http://security.cucumberlinux.com/security/details.php?id=166https://github.com/vim/vim/commit/5a73e0ca54c77e067c3b12ea6f35e3e8681e8cf8https://groups.google.com/d/msg/vim_dev/sRT9BtjLWMk/BRtSXNU4BwAJhttps://lists.debian.org/debian-lts-announce/2019/08/msg00003.htmlhttps://lists.debian.org/debian-lts-announce/2022/01/msg00003.htmlhttps://usn.ubuntu.com/4582-1/http://openwall.com/lists/oss-security/2017/11/27/2http://security.cucumberlinux.com/security/details.php?id=166https://github.com/vim/vim/commit/5a73e0ca54c77e067c3b12ea6f35e3e8681e8cf8https://groups.google.com/d/msg/vim_dev/sRT9BtjLWMk/BRtSXNU4BwAJhttps://lists.debian.org/debian-lts-announce/2019/08/msg00003.htmlhttps://lists.debian.org/debian-lts-announce/2022/01/msg00003.htmlhttps://usn.ubuntu.com/4582-1/
2017-12-01
Published