---
title: "CVE-2004-1138\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2004-1138?format=md
keywords: index, follow
---

# CVE-2004-1138

Publication date 10 January 2005

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

VIM before 6.3 and gVim before 6.3 allow local users to execute arbitrary
commands via a file containing a crafted modeline that is executed when the
file is viewed using options such as (1) termcap, (2) printdevice, (3)
titleold, (4) filetype, (5) syntax, (6) backupext, (7) keymap, (8)
patchmode, or (9) langmenu.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| vim | 7.04 feisty | Fixed 7.0-164+1ubuntu7.2 |
| 6.10 edgy | Fixed 7.0-035+1ubuntu5.2 |
| 6.06 LTS dapper | Fixed 6.4-006+2ubuntu6.1 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1138)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2004-1138)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2004-1138)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2004-1138)

### Related Ubuntu Security Notices (USN)

+ [USN-52-1](https://usn.ubuntu.com/USN-52-1)
+ vim vulnerability
+ 23 December 2004

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2004-1138>
