RHSA-2008:0617: Moderate: vim security update

Published Nov 25, 2008
·
Updated

Vim (Visual editor IMproved) is an updated and improved version of the vieditor.Several input sanitization flaws were found in Vim's keyword and taghandling. If Vim looked up a document's maliciously crafted tag or keyword,it was possible to execute arbitrary code as the user running Vim.(CVE-2008-4101)A heap-based overflow flaw was discovered in Vim's expansion of file namepatterns with shell wildcards. An attacker could create a specially-craftedfile or directory name that, when opened by Vim, caused the application tocrash or, possibly, execute arbitrary code. (CVE-2008-3432)Several input sanitization flaws were found in various Vim systemfunctions. If a user opened a specially crafted file, it was possible toexecute arbitrary code as the user running Vim. (CVE-2008-2712)Ulf Härnhammar, of Secunia Research, discovered a format string flaw inVim's help tag processor. If a user was tricked into executing the"helptags" command on malicious data, arbitrary code could be executed withthe permissions of the user running Vim. (CVE-2007-2953)All Vim users are advised to upgrade to these updated packages, whichcontain backported patches to correct these issues.

Affected Software

4 affected componentsFixes available
redhat/vim<6.3.046-1.el4_7.5
6.3.046-1.el4_7.5
redhat/vim-common<6.3.046-1.el4_7.5
6.3.046-1.el4_7.5
redhat/vim-enhanced<6.3.046-1.el4_7.5
6.3.046-1.el4_7.5
redhat/vim-minimal<6.3.046-1.el4_7.5
6.3.046-1.el4_7.5

Remediation

Event History

Nov 25, 2008
Advisory Published
via Red Hat·12:00 AM

Frequently Asked Questions

1

What is the severity of RHSA-2008:0617?

The severity of RHSA-2008:0617 is classified as high due to input sanitization flaws that may allow arbitrary code execution.

2

How do I fix RHSA-2008:0617?

To fix RHSA-2008:0617, update Vim and its related packages to version 6.3.046-1.el4_7.5 or later.

3

What software is affected by RHSA-2008:0617?

RHSA-2008:0617 affects Vim, vim-common, vim-enhanced, and vim-minimal packages.

4

What are the potential risks of not addressing RHSA-2008:0617?

Failure to address RHSA-2008:0617 can leave your system vulnerable to code execution attacks from maliciously crafted tags or keywords.

5

Is RHSA-2008:0617 specific to a particular operating system version?

Yes, RHSA-2008:0617 is specific to Red Hat Enterprise Linux 4.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203