First published: Thu Jan 13 2005(Updated: )
The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Vim by Vim Development Group | =6.3.011 | |
Vim by Vim Development Group | =6.3.025 | |
Vim by Vim Development Group | =6.3.044 | |
Vim by Vim Development Group | =6.3.030 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0069 is classified as a moderate severity vulnerability that allows local users to conduct symlink attacks.
To remediate CVE-2005-0069, upgrade to a fixed version of Vim that addresses the symlink vulnerability.
CVE-2005-0069 affects Vim versions 6.3.011, 6.3.025, 6.3.030, and 6.3.044.
Local users on systems running the affected versions of Vim are at risk from CVE-2005-0069.
The impact of CVE-2005-0069 includes the potential for local users to overwrite or create arbitrary files on the system.