CVE Vulnerabilities

CVE-2009-0316

Published: Jan 28, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983), as demonstrated by an erroneous search path for plugin/bike.vim in bicyclerepair.

Affected Software

NameVendorStart VersionEnd Version
VimVim*7.2 (including)
VimVim1.0 (including)1.0 (including)
VimVim1.22 (including)1.22 (including)
VimVim3.0 (including)3.0 (including)
VimVim4.0 (including)4.0 (including)
VimVim5.0 (including)5.0 (including)
VimVim5.1 (including)5.1 (including)
VimVim5.2 (including)5.2 (including)
VimVim5.3 (including)5.3 (including)
VimVim5.4 (including)5.4 (including)
VimVim5.5 (including)5.5 (including)
VimVim5.6 (including)5.6 (including)
VimVim5.7 (including)5.7 (including)
VimVim5.8 (including)5.8 (including)
VimVim6.0 (including)6.0 (including)
VimVim6.1 (including)6.1 (including)
VimVim6.2 (including)6.2 (including)
VimVim6.3 (including)6.3 (including)
VimVim6.4 (including)6.4 (including)
VimVim7.0 (including)7.0 (including)
VimVim7.1 (including)7.1 (including)
VimUbuntudapper*
VimUbuntugutsy*
VimUbuntuhardy*
VimUbuntuintrepid*
VimUbuntuupstream*

References