[Secure-testing-commits] r5778 - data/CVE

Florian Weimer fw at alioth.debian.org
Fri May 4 16:41:19 UTC 2007


Author: fw
Date: 2007-05-04 16:41:14 +0000 (Fri, 04 May 2007)
New Revision: 5778

Modified:
   data/CVE/list
Log:
CVE-2007-2438: vim


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2007-05-04 16:07:04 UTC (rev 5777)
+++ data/CVE/list	2007-05-04 16:41:14 UTC (rev 5778)
@@ -82,7 +82,8 @@
 CVE-2007-2439
 	RESERVED
 CVE-2007-2438 (The sandbox for vim allows dangerous functions such as (1) writefile, ...)
-	TODO: check
+	- vim <unfixed> (medium)
+	NOTE: Exploitable through modelines.
 CVE-2007-2437 (The X render (Xrender) extension in X.org X Window System 7.0, 7.1, ...)
 	TODO: check
 CVE-2007-2436 (The nl_fib_lookup function in net/ipv4/fib_frontend.c in Linux Kernel ...)




More information about the Secure-testing-commits mailing list