CVE-2004-1138: High severity vim development group vim vulnerability
VIM before 6.3 and gVim before 6.3 allow local users to execute arbitrary commands via a file containing a crafted modeline that is executed when the file is viewed using options such as (1) termcap, (2) printdevice, (3) titleold, (4) filetype, (5) syntax, (6) backupext, (7) keymap, (8) patchmode, or (9) langmenu.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1138?
CVE-2004-1138 is classified as a high severity vulnerability due to its ability to allow local users to execute arbitrary commands.
How do I fix CVE-2004-1138?
To fix CVE-2004-1138, upgrade to Vim 6.3 or later which contains the necessary patches addressing this vulnerability.
Who is affected by CVE-2004-1138?
CVE-2004-1138 affects local users of Vim versions prior to 6.3 across multiple versions including 5.0 to 6.2.
What vulnerabilities are similar to CVE-2004-1138?
Similar vulnerabilities include various command injection vulnerabilities in text editors that allow arbitrary code execution through crafted files.
Can CVE-2004-1138 be exploited remotely?
No, CVE-2004-1138 requires local access to the system to exploit the vulnerability.