CVE-2008-4101: Input Validation

Published Sep 11, 2008
·
Updated

Description of problem:

Ben Schmidt has discovered the following security flaw in Vim, which could lead to arbitrary code execution. Insufficient sanitization can lead to Vim executing arbitrary commands when performing keyword or tag lookup.

Flaw description pasted from original rdancer.org report (see [1]):

3.1. Keyword Lookup -- The K'' Command 3.1.1. Shell Commands and Ex Commands

Because the string passed to the shell for execution is not sanitized, it is possible to specify arbitrary shell commands where Vim expects an argument for the keyword program. Same applies to arbitrary Ex commands.

3.1.2. Keyword Program Command Line Switches

It is possible to specify command line switches for the keyword program in place of the argument. The gravity of this vulnerability depends on the keyword program selected. GNU man, the default keyword program in many installations, supports for example the --pager'' option (cf. the GNU man(1) manual page). This allows arbitrary command execution.

3.2. Tag Lookup -- the Control-]'' and g]'' Commands

Insufficient sanitization of an Ex command argument allows specifying additional arbitrary Ex commands in place of the argument.

3.3. Unknown Shell/Keyword Program

Because the syntax of the shell that is being used to execute the commands is not known beforehand, there may be other unknown vulnerabilities, that are present depending on the shell being used. Ditto for the man(1) program, and other keyword programs.

Version-Release number of selected component (if applicable): 3.0--current, possibly older

How reproducible: Always

Steps to Reproduce: 1. See part "4.EXPLOIT" from the original rdancer.org report [1] Actual results: Arbitrary code execution possible

Expected results: No security flaw present.

References:

[1] http://www.rdancer.org/vulnerablevim-K.html

Proposed patch:

Report: http://groups.google.com/group/vimdev/msg/dd32ad3a84f36bb2 Patch: http://groups.google.com/group/vimdev/attach/dd32ad3a84f36bb2/K-arbitrary-command-execution.patch?part=2

RH SRT official statement:

This issue affects all versions of the vim-enhanced package, as shipped with Red Hat Enterprise Linux 2.1, 3, 4 and 5 and within Fedora releases of 8, 9 and 10.

Other sources

Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) followed by a command, or execute arbitrary Ex commands by entering an argument after a (2) "Ctrl-]" (control close-square-bracket) or (3) "g]" (g close-square-bracket) keystroke sequence, a different issue than CVE-2008-2712.

MITRE

Affected Software

19 affected components
vim Vim<=7.2
vim Vim=3.0
vim Vim=4.0
vim Vim=5.0
vim Vim=5.1
vim Vim=5.2
vim Vim=5.3
vim Vim=5.4
vim Vim=5.5
vim Vim=5.6
vim Vim=5.7
vim Vim=5.8
vim Vim=6.0
vim Vim=6.1
vim Vim=6.2
vim Vim=6.3
vim Vim=6.4
vim Vim=7.0
vim Vim=7.1

Event History

Sep 11, 2008
Data Sourced
02:11 PM
DescriptionSeverityAffected Software
Sep 18, 2008
CVE Published
via MITRE·05:47 PM
Data Sourced
via MITRE·05:47 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2008-4101?

CVE-2008-4101 has a high severity level due to the potential for arbitrary code execution.

2

How do I fix CVE-2008-4101?

To fix CVE-2008-4101, you should update Vim to a version that has addressed this vulnerability.

3

Which versions of Vim are affected by CVE-2008-4101?

CVE-2008-4101 affects multiple versions of Vim, including versions 3.0 to 7.2.

4

Can CVE-2008-4101 be exploited remotely?

Yes, CVE-2008-4101 can potentially be exploited remotely by an attacker.

5

What are the potential impacts of CVE-2008-4101?

Exploiting CVE-2008-4101 may allow attackers to execute arbitrary commands on the affected system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203