CVE Vulnerabilities

CVE-2009-0316

Published: Jan 28, 2009 | Modified: Aug 08, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW

Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983), as demonstrated by an erroneous search path for plugin/bike.vim in bicyclerepair.

Affected Software

Name Vendor Start Version End Version
Vim Vim * 7.2 (including)
Vim Vim 1.0 (including) 1.0 (including)
Vim Vim 1.22 (including) 1.22 (including)
Vim Vim 3.0 (including) 3.0 (including)
Vim Vim 4.0 (including) 4.0 (including)
Vim Vim 5.0 (including) 5.0 (including)
Vim Vim 5.1 (including) 5.1 (including)
Vim Vim 5.2 (including) 5.2 (including)
Vim Vim 5.3 (including) 5.3 (including)
Vim Vim 5.4 (including) 5.4 (including)
Vim Vim 5.5 (including) 5.5 (including)
Vim Vim 5.6 (including) 5.6 (including)
Vim Vim 5.7 (including) 5.7 (including)
Vim Vim 5.8 (including) 5.8 (including)
Vim Vim 6.0 (including) 6.0 (including)
Vim Vim 6.1 (including) 6.1 (including)
Vim Vim 6.2 (including) 6.2 (including)
Vim Vim 6.3 (including) 6.3 (including)
Vim Vim 6.4 (including) 6.4 (including)
Vim Vim 7.0 (including) 7.0 (including)
Vim Vim 7.1 (including) 7.1 (including)
Vim Ubuntu dapper *
Vim Ubuntu gutsy *
Vim Ubuntu hardy *
Vim Ubuntu intrepid *
Vim Ubuntu upstream *

References