First published: Tue Oct 31 2017(Updated: )
VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the vi binary.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Vim | <=8.0.1187 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000382 has a medium severity rating due to potential unauthorized access to sensitive data.
To fix CVE-2017-1000382, update VIM to version 8.0.1190 or later where this issue is resolved.
CVE-2017-1000382 affects VIM versions up to 8.0.1187 inclusively.
CVE-2017-1000382 allows the creation of swap files that may be world readable, leading to potential data leaks.
Yes, if VIM is run with elevated privileges, CVE-2017-1000382 increases the risk of exposing sensitive files to unintended users.