CVE Vulnerabilities

CVE-2007-2953

Published: Jul 31, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a help-tags tag in a help file, related to the helptags command.

Affected Software

Name Vendor Start Version End Version
Vim Vim_development_group * 6.4 (including)
Vim Vim_development_group 7.0 (including) 7.0 (including)
Vim Vim_development_group 7.1 (including) 7.1 (including)
Vim Vim_development_group 7.1.38 (including) 7.1.38 (including)
Red Hat Enterprise Linux 3 RedHat vim-1:6.3.046-0.30E.11 *
Red Hat Enterprise Linux 4 RedHat vim-1:6.3.046-1.el4_7.5z *
Red Hat Enterprise Linux 5 RedHat vim-2:7.0.109-4.el5_2.4z *
Vim Ubuntu dapper *
Vim Ubuntu edgy *
Vim Ubuntu feisty *

References