Untrusted search path in Vim - CVE-2009-0316

 

Untrusted search path in Vim - CVE-2009-0316

Published: December 27, 2022


Vulnerability identifier: #VU70497
CSH Severity: Low
CVSS v4: 5.4 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2009-0316
CWE-ID: CWE-426
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to untrusted search path in src/if_python.c in the Python interface in Vim. A local user can place a malicious python file in a directory and trick the victim to open a file in that directory.


Affected software

Vim
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
EMC Cloud Tiering Appliance
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
Dell Secure Connect Gateway
vim-data
vim-data-common
gvim
gvim-debuginfo
vim
vim-debuginfo
vim-debugsource

How to mitigate CVE-2009-0316

Install updates from vendor's website.

Vim - update to 7.2.045
EMC ViPR SRM - update to 4.9.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
Dell Secure Connect Gateway - update to 5.14.00.16
vim-data - update to 9.0.0814-17.9.1
vim-data-common - update to 9.0.0814-17.9.1
gvim - update to 9.0.0814-17.9.1
gvim-debuginfo - update to 9.0.0814-17.9.1
vim - update to 9.0.0814-17.9.1
vim-debuginfo - update to 9.0.0814-17.9.1
vim-debugsource - update to 9.0.0814-17.9.1
EMC Cloud Tiering Appliance - update to 13.1.0.2.29

External References

Related Security Bulletins