Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983), as demonstrated by an erroneous search path for plugin/bike.vim in bicyclerepair.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vim | Vim | * | 7.2 (including) |
Vim | Vim | 1.0 (including) | 1.0 (including) |
Vim | Vim | 1.22 (including) | 1.22 (including) |
Vim | Vim | 3.0 (including) | 3.0 (including) |
Vim | Vim | 4.0 (including) | 4.0 (including) |
Vim | Vim | 5.0 (including) | 5.0 (including) |
Vim | Vim | 5.1 (including) | 5.1 (including) |
Vim | Vim | 5.2 (including) | 5.2 (including) |
Vim | Vim | 5.3 (including) | 5.3 (including) |
Vim | Vim | 5.4 (including) | 5.4 (including) |
Vim | Vim | 5.5 (including) | 5.5 (including) |
Vim | Vim | 5.6 (including) | 5.6 (including) |
Vim | Vim | 5.7 (including) | 5.7 (including) |
Vim | Vim | 5.8 (including) | 5.8 (including) |
Vim | Vim | 6.0 (including) | 6.0 (including) |
Vim | Vim | 6.1 (including) | 6.1 (including) |
Vim | Vim | 6.2 (including) | 6.2 (including) |
Vim | Vim | 6.3 (including) | 6.3 (including) |
Vim | Vim | 6.4 (including) | 6.4 (including) |
Vim | Vim | 7.0 (including) | 7.0 (including) |
Vim | Vim | 7.1 (including) | 7.1 (including) |
Vim | Ubuntu | dapper | * |
Vim | Ubuntu | gutsy | * |
Vim | Ubuntu | hardy | * |
Vim | Ubuntu | intrepid | * |
Vim | Ubuntu | upstream | * |