---
title: "CVE-2008-3076\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2008-3076?format=md
keywords: index, follow
---

# CVE-2008-3076

Publication date 21 February 2009

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted
attackers to execute arbitrary code via shell metacharacters in filenames
used by the execute and system functions within the (1) mz and (2) mc
commands, as demonstrated by the netrw.v2 and netrw.v3 test cases. NOTE:
this issue reportedly exists because of an incomplete fix for
CVE-2008-2712.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2008-3076?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| vim | 8.10 intrepid | Not affected |
| 8.04 LTS hardy | Not affected |
| 7.10 gutsy | Not affected |
| 6.06 LTS dapper | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

This was patched in vim from usn-712-1

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3076)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2008-3076)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2008-3076)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2008-3076)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2008-3076>
