You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa vim

Sigurnosni nedostaci programskog paketa vim

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-4582-1
October 14, 2020

vim vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in Vim.

Software Description:
– vim: Vi IMproved – enhanced vi editor

Details:

It was discovered that Vim incorrectly handled permissions on the .swp
file. A local attacker could possibly use this issue to obtain sensitive
information. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-17087)

It was discovered that Vim incorrectly handled restricted mode. A local
attacker could possibly use this issue to bypass restricted mode and
execute arbitrary commands. Note: This update only makes executing shell
commands more difficult. Restricted mode should not be considered a
complete security measure. (CVE-2019-20807)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
vim 2:8.0.1453-1ubuntu1.4
vim-common 2:8.0.1453-1ubuntu1.4
vim-runtime 2:8.0.1453-1ubuntu1.4

Ubuntu 16.04 LTS:
vim 2:7.4.1689-3ubuntu1.5
vim-common 2:7.4.1689-3ubuntu1.5
vim-runtime 2:7.4.1689-3ubuntu1.5

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4582-1
CVE-2017-17087, CVE-2019-20807

Package Information:
https://launchpad.net/ubuntu/+source/vim/2:8.0.1453-1ubuntu1.4
https://launchpad.net/ubuntu/+source/vim/2:7.4.1689-3ubuntu1.5

—–BEGIN PGP SIGNATURE—–

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl+HOD8ACgkQZWnYVadE
vpNGSRAAjUhdbsHUzR1y6So+PCLBQ+2Sq7xVq6ZZu+B4A9lCDUCw+JPijlqP393m
/b2ryFVF3jxi10anBGkdDzsR5a5HPIk2fT9IB1Sokd37Xla6YHtEyQvBb9R5TgAp
1wTxDSUWIZdY2FfNJlenWtbbdpi8GRrge57eWQl50MnW5WY/uvu/Hez6MXGA9xT9
ipxg9b2Af1w2OEYaEuHf7uswZ6+V3vC8QTCKe2JT/Y/d4ZjQJmQXDycqGHutVbJ7
7p565Ev1Qm85/cEJ8yrmXaLQWOPN/bR18oUNB+KLh1uUZKUfzGi1F31Tz7bpn7Eh
J0WIYWRAQI5ukh15ZylvMRQNRrufWuLCLsdPt+/Oqz9TRi6IIaQCTE83SWuCWiya
m8o09Rk7PX++b14W+lKpcqesTU6EDgTqAejG7Bk1v4lU6FVwfqNTRf4bM8Xn3M6/
RJGFj+N4aBWkdsETBcekIGrypXUNyKkewM89JiAoUsPslbHElwlQ+LwkKLQuEBO2
dMzHxpvix/jn+l+g1Joa+JwvfKCXIYQk/dVsupDCc+GZwcwktJl2r/QIqPI8Ka1U
G0ryQGRm371liB+xpEZI1m1O21aiFfFPh+Qjg4rp6mOaQFLyZADjUAnyg10h9AYt
e7OkNHCIS1xzqs+BN7mMNJkbJEyWJ5CdjEgoyycB9/+V24HR0y8=
=eO0m
—–END PGP SIGNATURE—–

AutorBruno Varga
Cert idNCERT-REF-2020-10-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa python

Otkriven je sigurnosni nedostatak u programskom paketu python za operacijski sustav Ubuntu. Otkriveni nedostatak potencijalnim napadačima omogućuje izvođenje ‘CRLF injection’...

Close