CVE Database
/

CVE-2008-3074

Back to search

CVE-2008-3074

Published: Feb 21, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exclamation point) shell metacharacter in (1) the filename of a tar archive and possibly (2) the filename of the first file in a tar archive, which is not properly handled by the VIM TAR plugin (tar.vim) v.10 through v.22, as demonstrated by the shellescape, tarplugin.v2, tarplugin, and tarplugin.updated test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712. NOTE: this issue has the same root cause as CVE-2008-3075. NOTE: due to the complexity of the associated disclosures and the incomplete information related to them, there may be inaccuracies in this CVE description and in external mappings to this identifier.

VendorProductVersions

n/a

n/a

affected
n/a

References

SUSE-SR:2009:007
vendor-advisory
x_refsource_SUSE
[oss-security] 20081020 CVE request (vim)
mailing-list
x_refsource_MLIST
32462
vdb-entry
x_refsource_BID
oval:org.mitre.oval:def:10754
vdb-entry
signature
x_refsource_OVAL
RHSA-2008:0580
vendor-advisory
x_refsource_REDHAT
34418
third-party-advisory
x_refsource_SECUNIA
MDVSA-2008:236
vendor-advisory
x_refsource_MANDRIVA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now