ISOMAN

CVE

CVE-2019-20807

In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).

Severity
MEDIUM
CVSS
5.3
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
Ubuntu18.04.6 amd64 desktopunknownsource
Ubuntu18.04.6 amd64 live-serverunknownsource

References

  1. http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00018.html
  2. http://seclists.org/fulldisclosure/2020/Jul/24
  3. https://github.com/vim/vim/commit/8c62a08faf89663e5633dc5036cd8695c80f1075
  4. https://github.com/vim/vim/releases/tag/v8.1.0881
  5. https://lists.debian.org/debian-lts-announce/2022/01/msg00003.html
  6. https://support.apple.com/kb/HT211289
  7. https://usn.ubuntu.com/4582-1/
  8. https://www.starwindsoftware.com/security/sw-20220812-0003/
  9. http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00018.html
  10. http://seclists.org/fulldisclosure/2020/Jul/24
  11. https://github.com/vim/vim/commit/8c62a08faf89663e5633dc5036cd8695c80f1075
  12. https://github.com/vim/vim/releases/tag/v8.1.0881
  13. https://lists.debian.org/debian-lts-announce/2022/01/msg00003.html
  14. https://support.apple.com/kb/HT211289
  15. https://usn.ubuntu.com/4582-1/
  16. https://www.starwindsoftware.com/security/sw-20220812-0003/