[LFS Trac] #5877: vim-9.2.0078 (Security update)
| Newsgroups | gmane.linux.lfs.book |
|---|---|
| Message-ID | <[email protected]> |
#5877: vim-9.2.0078 (Security update)
-------------------------+----------------------
Reporter: Bruce Dubbs | Owner: lfs-book
Type: enhancement | Status: new
Priority: normal | Milestone: 13.1
Component: Book | Version: git
Severity: normal | Keywords:
-------------------------+----------------------
# Summary
An OS command injection vulnerability exists in the `netrw` standard
plugin bundled with Vim. By inducing a user to open a crafted URL (e.g.,
using the`scp://` protocol handler), an attacker can execute arbitrary
shell commands with the privileges
of the Vim process.
--
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/5877>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.
--
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page