Your submission was sent successfully! Close

USN-463-1: vim vulnerability

23 May 2007

vim vulnerability



Tomas Golembiovsky discovered that some vim commands were accidentally
allowed in modelines. By tricking a user into opening a specially
crafted file in vim, an attacker could execute arbitrary code with user

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 7.04
  • vim - 1:7.0-164+1ubuntu7.1
Ubuntu 6.10
  • vim - 1:7.0-035+1ubuntu5.1

In general, a standard system upgrade is sufficient to effect the
necessary changes.