OS Command Injection in Vim - CVE-2019-20807

 

OS Command Injection in Vim - CVE-2019-20807

Published: May 28, 2020 / Updated: July 17, 2020


Vulnerability identifier: #VU30281
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-20807
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to read and manipulate data.

In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).


Affected software

Vim
Amazon Linux AMI
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Ubuntu
Opensuse
Tanzu Greenplum for Kubernetes
Service Telemetry Framework
Isolation Segment
VMware Tanzu Application Service for VMs
VMware Tanzu Operations Manager
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
vim-runtime (Ubuntu package)
vim-common (Ubuntu package)
vim (Ubuntu package)
vim (Red Hat package)
vim-X11
vim-common
vim-enhanced
vim-minimal
vim-filesystem

How to mitigate CVE-2019-20807

Install update from vendor's website.

Vim - update to 8.1.0881
Tanzu Greenplum for Kubernetes - update to 2.0.0
Isolation Segment - addressed in versions 2.7.26, 2.8.20, 2.9.14, 2.10.6
VMware Tanzu Application Service for VMs - addressed in versions 2.7.27, 2.8.21, 2.9.15, 2.10.7
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.9.12, 2.10.3
Quay - update to 3.3.3
vim-runtime (Ubuntu package) - addressed in versions 2:7.4.1689-3ubuntu1.5, 2:8.0.1453-1ubuntu1.4
vim-common (Ubuntu package) - addressed in versions 2:7.4.1689-3ubuntu1.5, 2:8.0.1453-1ubuntu1.4
vim (Ubuntu package) - addressed in versions 2:7.4.1689-3ubuntu1.5, 2:8.0.1453-1ubuntu1.4, 2:8.0.1453-1ubuntu1.7, 2:8.1.2269-1ubuntu5.4, 2:8.2.2434-1ubuntu1.2, 2:8.2.2434-3ubuntu3.1
vim (Red Hat package) - update to 8.0.1763-15.el8
vim-X11 - update to 8.0.1763-16.0.1
vim-common - update to 8.0.1763-16.0.1
vim-enhanced - update to 8.0.1763-16.0.1
vim-minimal - update to 8.0.1763-16.0.1
vim-filesystem - update to 8.0.1763-16.0.1

External References

Related Security Bulletins