Information disclosure in Vim - CVE-2017-17087
Published: December 1, 2017 / Updated: July 17, 2020
Vulnerability details
The vulnerability allows a local authenticated user to gain access to sensitive information.
fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.
Affected software
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
Tanzu Greenplum for Kubernetes
EMC Cloud Tiering Appliance
Isolation Segment
VMware Tanzu Application Service for VMs
Dell Secure Connect Gateway
VMware Tanzu Operations Manager
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
RecoverPoint for VMs
Dell EMC VxRail Appliance
vim-runtime (Ubuntu package)
vim-common (Ubuntu package)
vim (Ubuntu package)
vim-small
gvim
gvim-debuginfo
vim
vim-debuginfo
vim-data-common
vim-data
vim-small-debuginfo
vim-debugsource
How to mitigate CVE-2017-17087
Tanzu Greenplum for Kubernetes - update to 2.0.0
Isolation Segment - addressed in versions 2.7.26, 2.8.20, 2.9.14, 2.10.6
VMware Tanzu Application Service for VMs - addressed in versions 2.7.27, 2.8.21, 2.9.15, 2.10.7
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.9.12, 2.10.3
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
EMC ViPR SRM - update to 4.9.0.0
Dell Secure Connect Gateway - update to 5.14.00.16
RecoverPoint for VMs - update to 6.0.SP1.P1
Dell EMC VxRail Appliance - addressed in versions 7.0.372, 8.0.000
vim-runtime (Ubuntu package) - addressed in versions 2:7.4.1689-3ubuntu1.5, 2:8.0.1453-1ubuntu1.4
vim-common (Ubuntu package) - addressed in versions 2:7.4.1689-3ubuntu1.5, 2:8.0.1453-1ubuntu1.4
vim (Ubuntu package) - addressed in versions 2:7.4.1689-3ubuntu1.5, 2:8.0.1453-1ubuntu1.4, 2:8.0.1453-1ubuntu1.7, 2:8.1.2269-1ubuntu5.4, 2:8.2.2434-1ubuntu1.2, 2:8.2.2434-3ubuntu3.1
vim-small - update to 8.2.5038-150000.5.21.1
gvim - addressed in versions 8.2.5038-150000.5.21.1, 9.0.0814-17.9.1
gvim-debuginfo - addressed in versions 8.2.5038-150000.5.21.1, 9.0.0814-17.9.1
vim - addressed in versions 8.2.5038-150000.5.21.1, 9.0.0814-17.9.1
vim-debuginfo - addressed in versions 8.2.5038-150000.5.21.1, 9.0.0814-17.9.1
vim-data-common - addressed in versions 8.2.5038-150000.5.21.1, 9.0.0814-17.9.1
vim-data - addressed in versions 8.2.5038-150000.5.21.1, 9.0.0814-17.9.1
vim-small-debuginfo - update to 8.2.5038-150000.5.21.1
vim-debugsource - addressed in versions 8.2.5038-150000.5.21.1, 9.0.0814-17.9.1
EMC Cloud Tiering Appliance - update to 13.1.0.2.29
External References
- http://openwall.com/lists/oss-security/2017/11/27/2
- http://security.cucumberlinux.com/security/details.php?id=166
- https://github.com/vim/vim/commit/5a73e0ca54c77e067c3b12ea6f35e3e8681e8cf8
- https://groups.google.com/d/msg/vim_dev/sRT9BtjLWMk/BRtSXNU4BwAJ
- https://lists.debian.org/debian-lts-announce/2019/08/msg00003.html
Related Security Bulletins
- Information disclosure in Vim
- Multiple vulnerabilities in VMware Products
- Ubuntu update for vim
- SUSE update for vim
- Multiple vulnerabilities in Dell VxRail
- SUSE update for vim
- Multiple vulnerabilities in Dell VxRail Appliance components
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- Ubuntu update for vim