Input validation error in Vim - CVE-2016-1248
Published: August 3, 2020 / Updated: June 17, 2021
Vulnerability identifier: #VU33140
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-1248
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
im before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execution of arbitrary code if a file with a specially crafted modeline is opened.
Affected software
Vim
Arch Linux
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server for ARM
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux Server - AUS
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Opensuse
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
EMC Cloud Tiering Appliance
neovim (Alpine package)
vim (Red Hat package)
vim-data
vim-data-common
gvim
gvim-debuginfo
vim
vim-debuginfo
vim-debugsource
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
Dell Secure Connect Gateway
Arch Linux
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server for ARM
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux Server - AUS
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Opensuse
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
EMC Cloud Tiering Appliance
neovim (Alpine package)
vim (Red Hat package)
vim-data
vim-data-common
gvim
gvim-debuginfo
vim
vim-debuginfo
vim-debugsource
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
Dell Secure Connect Gateway
How to mitigate CVE-2016-1248
Install updates from vendor's website.
Vim - update to 8.0.0056
neovim (Alpine package) - update to 0.1.6-r1
EMC ViPR SRM - update to 4.9.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
Dell Secure Connect Gateway - update to 5.14.00.16
vim (Red Hat package) - addressed in versions 7.4.160-1.el7_3.1, 7.4.629-5.el6_8.1
vim-data - update to 9.0.0814-17.9.1
vim-data-common - update to 9.0.0814-17.9.1
gvim - update to 9.0.0814-17.9.1
gvim-debuginfo - update to 9.0.0814-17.9.1
vim - update to 9.0.0814-17.9.1
vim-debuginfo - update to 9.0.0814-17.9.1
vim-debugsource - update to 9.0.0814-17.9.1
EMC Cloud Tiering Appliance - update to 13.1.0.2.29
neovim (Alpine package) - update to 0.1.6-r1
EMC ViPR SRM - update to 4.9.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
Dell Secure Connect Gateway - update to 5.14.00.16
vim (Red Hat package) - addressed in versions 7.4.160-1.el7_3.1, 7.4.629-5.el6_8.1
vim-data - update to 9.0.0814-17.9.1
vim-data-common - update to 9.0.0814-17.9.1
gvim - update to 9.0.0814-17.9.1
gvim-debuginfo - update to 9.0.0814-17.9.1
vim - update to 9.0.0814-17.9.1
vim-debuginfo - update to 9.0.0814-17.9.1
vim-debugsource - update to 9.0.0814-17.9.1
EMC Cloud Tiering Appliance - update to 13.1.0.2.29
Links to Public Exploits and PoC-codes
External References
- http://openwall.com/lists/oss-security/2016/11/22/20
- http://rhn.redhat.com/errata/RHSA-2016-2972.html
- http://www.debian.org/security/2016/dsa-3722
- http://www.securityfocus.com/bid/94478
- http://www.securitytracker.com/id/1037338
- http://www.ubuntu.com/usn/USN-3139-1
- https://anonscm.debian.org/cgit/pkg-vim/vim.git/tree/debian/changelog
- https://github.com/neovim/neovim/commit/4fad66fbe637818b6b3d6bc5d21923ba72795040
- https://github.com/vim/vim/commit/d0b5138ba4bccff8a744c99836041ef6322ed39a
- https://github.com/vim/vim/releases/tag/v8.0.0056
- https://lists.debian.org/debian-lts-announce/2016/11/msg00025.html
- https://lists.debian.org/debian-security-announce/2016/msg00305.html
- https://security.gentoo.org/glsa/201701-29
Related Security Bulletins
- Remote code execution in Vim
- OpenSUSE Linux update for vim
- OpenSUSE Linux update for vim
- SUSE Linux update for vim
- SUSE Linux update for vim
- Input validation error in neovim (Alpine package)
- Arch Linux update for neovim
- Amazon Linux AMI update for vim
- Gentoo update for Vim, gVim
- SUSE update for vim
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Dell Data Protection Central
- Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7 update for vim