CVE-2002-1377
Published Dec 23, 2002
Last updated 7 years ago
Overview
- Description
- vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which are not sandboxed but may be executed when vim is used to edit a malicious file, as demonstrated using mutt.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.6
- Impact score
- 6.4
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:vim_development_group:vim:5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0B6461B4-AD69-4E54-901D-CB354FE9061C" }, { "criteria": "cpe:2.3:a:vim_development_group:vim:5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D51F522E-E7A6-4861-BE54-C76B5D6062AB" }, { "criteria": "cpe:2.3:a:vim_development_group:vim:5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5B5306C4-D4FA-48FE-B72A-8ED231DF283A" }, { "criteria": "cpe:2.3:a:vim_development_group:vim:5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D8C559F4-82E7-4BFA-B1C2-AAD1EA790DE7" }, { "criteria": "cpe:2.3:a:vim_development_group:vim:5.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FD83B9EE-82FF-4DA5-8577-97CE226EFEAF" }, { "criteria": "cpe:2.3:a:vim_development_group:vim:5.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "823E99C7-7020-48B2-8F71-6FA5A1097EC0" }, { "criteria": "cpe:2.3:a:vim_development_group:vim:5.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0A5B6675-BF67-434D-8D64-7BA6029A6BD4" }, { "criteria": "cpe:2.3:a:vim_development_group:vim:5.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "826F3339-8674-4A84-8EAC-17C884BBF723" }, { "criteria": "cpe:2.3:a:vim_development_group:vim:5.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2A7C7C4D-9E38-40A1-B003-939F46CD96CC" }, { "criteria": "cpe:2.3:a:vim_development_group:vim:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D3A7789A-E0B0-45EA-B05A-A5A1BF31A24D" }, { "criteria": "cpe:2.3:a:vim_development_group:vim:6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D6FF1779-4A0A-4E9E-94E1-5F7C4EF0555B" } ], "operator": "OR" } ] } ]