CVE-2010-3914: Critical severity suse vim vulnerability
Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3914?
CVE-2010-3914 is classified as a medium severity vulnerability.
How do I fix CVE-2010-3914?
To fix CVE-2010-3914, update GVim to a version later than 7.3.034.
Who is affected by CVE-2010-3914?
Local users and possibly remote attackers are affected by CVE-2010-3914.
What type of attacks does CVE-2010-3914 facilitate?
CVE-2010-3914 facilitates arbitrary code execution and DLL hijacking attacks.
Which versions of GVim are vulnerable to CVE-2010-3914?
GVim versions before 7.3.034 and possibly other versions prior to 7.3.046 are vulnerable to CVE-2010-3914.