CVE-2008-6235

Publication date 21 February 2009

Last updated 24 July 2024


Ubuntu priority

The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a filename used by the (1) "D" (delete) command or (2) b:netrw_curdir variable, as demonstrated using the netrw.v4 and netrw.v5 test cases.

Read the notes from the security team

Status

Package Ubuntu Release Status
vim 8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
6.06 LTS dapper
Not affected

Notes


mdeslaur

This was patched in vim from usn-712-1