Novell Home

CVE-2008-3076

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2008-3076 at MITRE

Description

The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames used by the execute and system functions within the (1) mz and (2) mc commands, as demonstrated by the netrw.v2 and netrw.v3 test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712.

Novell/SUSE information

Novell Bugzilla entry: 406693

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 10.3
  • gvim >= 7.2-9.1
  • vim >= 7.2-9.1
  • vim-base >= 7.2-9.1
  • vim-data >= 7.2-9.1
  • vim-enhanced >= 7.2-9.1

© 2012 Novell