If you haven’t patched Vim or NeoVim tex t editors, you really, really should

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12LupSQQtUy+Qj7RQL0x3OYGDXYiXnusQV5=3FZR4oO1TA@mail.gmail.com>
'A recently patched vulnerability in text editors preinstalled in a
variety of Linux distributions allows hackers to take control of
computers when users open a malicious text file. The latest version of
Apple’s macOS is continuing to use a vulnerable version, although
attacks only work when users have changed a default setting that
enables a feature called modelines.

Vim and its forked derivative, NeoVim, contained a flaw that resided
in modelines. This feature lets users specify window dimensions and
other custom options near the start or end of a text file. While
modelines restricts the commands available and runs them inside a
sandbox that’s cordoned off from the operating system, researcher
Armin Razmjou noticed the source! command (including the bang on the
end) bypassed that protection.'

-- source: https://arstechnica.com/information-technology/2019/06/if-you-havent-patched-vim-or-neovim-text-editors-you-really-really-should/

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.