CVE-2004-1138

Publication date 10 January 2005

Last updated 24 July 2024


Ubuntu priority

VIM before 6.3 and gVim before 6.3 allow local users to execute arbitrary commands via a file containing a crafted modeline that is executed when the file is viewed using options such as (1) termcap, (2) printdevice, (3) titleold, (4) filetype, (5) syntax, (6) backupext, (7) keymap, (8) patchmode, or (9) langmenu.

Status

Package Ubuntu Release Status
vim 7.04 feisty
Fixed 7.0-164+1ubuntu7.2
6.10 edgy
Fixed 7.0-035+1ubuntu5.2
6.06 LTS dapper
Fixed 6.4-006+2ubuntu6.1

References

Related Ubuntu Security Notices (USN)

    • USN-52-1
    • vim vulnerability
    • 23 December 2004

Other references