CVE-2007-2953
vim format string flaw
Severity Score
6.8
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a help-tags tag in a help file, related to the helptags command.
Vulnerabilidad de cadena de formato en la función helptags_one de src/ex_cmds.c en Vim 6.4 y anteriores, y 7.x hasta 7.1, permite a atacantes remotos con la intervención del usuario ejecutar código de su elección mediante especificadores de cadena de formato en una etiqueta help-tags de un archivo de ayuda, relacionado con el comando helptags.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-05-31 CVE Reserved
- 2007-07-31 CVE Published
- 2024-07-11 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (34)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
ftp://ftp.vim.org/pub/vim/patches/7.1/7.1.039 | 2018-10-16 | |
http://secunia.com/advisories/25941 | 2018-10-16 | |
http://secunia.com/secunia_research/2007-66/advisory | 2018-10-16 | |
http://www.securityfocus.com/bid/25095 | 2018-10-16 |
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2007/dsa-1364 | 2018-10-16 | |
http://www.mandriva.com/security/advisories?name=MDKSA-2007:168 | 2018-10-16 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2008:236 | 2018-10-16 | |
http://www.novell.com/linux/security/advisories/2007_18_sr.html | 2018-10-16 | |
http://www.redhat.com/support/errata/RHSA-2008-0580.html | 2018-10-16 | |
http://www.redhat.com/support/errata/RHSA-2008-0617.html | 2018-10-16 | |
http://www.trustix.org/errata/2007/0026 | 2018-10-16 | |
http://www.ubuntu.com/usn/usn-505-1 | 2018-10-16 | |
https://access.redhat.com/security/cve/CVE-2007-2953 | 2008-11-25 | |
https://bugzilla.redhat.com/show_bug.cgi?id=248542 | 2008-11-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vim Development Group Search vendor "Vim Development Group" | Vim Search vendor "Vim Development Group" for product "Vim" | <= 6.4 Search vendor "Vim Development Group" for product "Vim" and version " <= 6.4" | - |
Affected
| ||||||
Vim Development Group Search vendor "Vim Development Group" | Vim Search vendor "Vim Development Group" for product "Vim" | 7.0 Search vendor "Vim Development Group" for product "Vim" and version "7.0" | - |
Affected
| ||||||
Vim Development Group Search vendor "Vim Development Group" | Vim Search vendor "Vim Development Group" for product "Vim" | 7.1 Search vendor "Vim Development Group" for product "Vim" and version "7.1" | - |
Affected
| ||||||
Vim Development Group Search vendor "Vim Development Group" | Vim Search vendor "Vim Development Group" for product "Vim" | 7.1.38 Search vendor "Vim Development Group" for product "Vim" and version "7.1.38" | - |
Affected
|