RHSA-2008:0617: Moderate: vim security update
Vim (Visual editor IMproved) is an updated and improved version of the vieditor.Several input sanitization flaws were found in Vim's keyword and taghandling. If Vim looked up a document's maliciously crafted tag or keyword,it was possible to execute arbitrary code as the user running Vim.(CVE-2008-4101)A heap-based overflow flaw was discovered in Vim's expansion of file namepatterns with shell wildcards. An attacker could create a specially-craftedfile or directory name that, when opened by Vim, caused the application tocrash or, possibly, execute arbitrary code. (CVE-2008-3432)Several input sanitization flaws were found in various Vim systemfunctions. If a user opened a specially crafted file, it was possible toexecute arbitrary code as the user running Vim. (CVE-2008-2712)Ulf Härnhammar, of Secunia Research, discovered a format string flaw inVim's help tag processor. If a user was tricked into executing the"helptags" command on malicious data, arbitrary code could be executed withthe permissions of the user running Vim. (CVE-2007-2953)All Vim users are advised to upgrade to these updated packages, whichcontain backported patches to correct these issues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2008:0617?
The severity of RHSA-2008:0617 is classified as high due to input sanitization flaws that may allow arbitrary code execution.
How do I fix RHSA-2008:0617?
To fix RHSA-2008:0617, update Vim and its related packages to version 6.3.046-1.el4_7.5 or later.
What software is affected by RHSA-2008:0617?
RHSA-2008:0617 affects Vim, vim-common, vim-enhanced, and vim-minimal packages.
What are the potential risks of not addressing RHSA-2008:0617?
Failure to address RHSA-2008:0617 can leave your system vulnerable to code execution attacks from maliciously crafted tags or keywords.
Is RHSA-2008:0617 specific to a particular operating system version?
Yes, RHSA-2008:0617 is specific to Red Hat Enterprise Linux 4.