CVE-2005-0069: Medium severity Vim Development Group Vim vulnerability
Published Jan 13, 2005
·Updated
The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.
Affected Software
4 affected components
Vim Development Group Vim=6.3.011
Vim Development Group Vim=6.3.025
Vim Development Group Vim=6.3.044
Vim Development Group Vim=6.3.030
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jan 13, 2005
CVE Published
05:00 AM
Jan 29, 2005
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0069?
CVE-2005-0069 is classified as a moderate severity vulnerability that allows local users to conduct symlink attacks.
2
How do I fix CVE-2005-0069?
To remediate CVE-2005-0069, upgrade to a fixed version of Vim that addresses the symlink vulnerability.
3
What are the affected versions in CVE-2005-0069?
CVE-2005-0069 affects Vim versions 6.3.011, 6.3.025, 6.3.030, and 6.3.044.
4
Who is at risk from CVE-2005-0069?
Local users on systems running the affected versions of Vim are at risk from CVE-2005-0069.
5
What is the impact of CVE-2005-0069?
The impact of CVE-2005-0069 includes the potential for local users to overwrite or create arbitrary files on the system.