First published: Thu May 28 2020(Updated: )
In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).
Credit: Guilherme de Almeida Suckevicz cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Catalina | <10.15.6 | 10.15.6 |
Apple Mojave | ||
Apple High Sierra | ||
ubuntu/vim | <2:8.0.1453-1ubuntu1.4 | 2:8.0.1453-1ubuntu1.4 |
ubuntu/vim | <2:7.4.052-1ubuntu3.1+ | 2:7.4.052-1ubuntu3.1+ |
ubuntu/vim | <2:8.1.2136-1 | 2:8.1.2136-1 |
ubuntu/vim | <2:7.4.1689-3ubuntu1.5 | 2:7.4.1689-3ubuntu1.5 |
Vim Vim | <8.1.0881 | |
Debian Debian Linux | =9.0 | |
openSUSE Leap | =15.1 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Apple Mac OS X | =10.13.6 | |
Apple Mac OS X | =10.14.6 | |
Starwindsoftware Command Center | =2-build_6003 | |
Starwindsoftware San \& Nas | =1.0-update_1 | |
debian/vim | 2:8.1.0875-5+deb10u2 2:8.1.0875-5+deb10u6 2:8.2.2434-3+deb11u1 2:9.0.1378-2 2:9.1.0377-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-20807 is a vulnerability in Vim that was addressed with improved checks.
CVE-2019-20807 affects macOS Catalina 10.15.6, Mojave, and High Sierra.
To fix CVE-2019-20807, update your macOS to the latest available version.
You can find more information about CVE-2019-20807 on the Apple support website.