CVE-2002-1377: Medium severity vim development group vim vulnerability
vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which are not sandboxed but may be executed when vim is used to edit a malicious file, as demonstrated using mutt.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1377?
CVE-2002-1377 is considered a critical vulnerability due to its ability to allow attackers to execute arbitrary commands.
How do I fix CVE-2002-1377?
To fix CVE-2002-1377, update Vim to version 6.2 or later, where this vulnerability is addressed.
Which versions of Vim are affected by CVE-2002-1377?
CVE-2002-1377 affects Vim versions 6.0 and 6.1, as well as prior versions like 5.0 through 5.8.
What attack vector is used in CVE-2002-1377?
CVE-2002-1377 can be exploited when Vim is used to edit a malicious file containing certain modelines.
What is the impact of CVE-2002-1377 on system security?
The impact of CVE-2002-1377 can lead to unauthorized command execution, compromising system security and user data.