OS Command Injection in Vim - CVE-2019-20807
Published: May 28, 2020 / Updated: July 17, 2020
Vulnerability identifier: #VU30281
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-20807
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local authenticated user to read and manipulate data.
In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).
Affected software
Vim
Amazon Linux AMI
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Ubuntu
Opensuse
Tanzu Greenplum for Kubernetes
Service Telemetry Framework
Isolation Segment
VMware Tanzu Application Service for VMs
VMware Tanzu Operations Manager
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
vim-runtime (Ubuntu package)
vim-common (Ubuntu package)
vim (Ubuntu package)
vim (Red Hat package)
vim-X11
vim-common
vim-enhanced
vim-minimal
vim-filesystem
Amazon Linux AMI
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Ubuntu
Opensuse
Tanzu Greenplum for Kubernetes
Service Telemetry Framework
Isolation Segment
VMware Tanzu Application Service for VMs
VMware Tanzu Operations Manager
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
vim-runtime (Ubuntu package)
vim-common (Ubuntu package)
vim (Ubuntu package)
vim (Red Hat package)
vim-X11
vim-common
vim-enhanced
vim-minimal
vim-filesystem
How to mitigate CVE-2019-20807
Install update from vendor's website.
Vim - update to 8.1.0881
Tanzu Greenplum for Kubernetes - update to 2.0.0
Isolation Segment - addressed in versions 2.7.26, 2.8.20, 2.9.14, 2.10.6
VMware Tanzu Application Service for VMs - addressed in versions 2.7.27, 2.8.21, 2.9.15, 2.10.7
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.9.12, 2.10.3
Quay - update to 3.3.3
vim-runtime (Ubuntu package) - addressed in versions 2:7.4.1689-3ubuntu1.5, 2:8.0.1453-1ubuntu1.4
vim-common (Ubuntu package) - addressed in versions 2:7.4.1689-3ubuntu1.5, 2:8.0.1453-1ubuntu1.4
vim (Ubuntu package) - addressed in versions 2:7.4.1689-3ubuntu1.5, 2:8.0.1453-1ubuntu1.4, 2:8.0.1453-1ubuntu1.7, 2:8.1.2269-1ubuntu5.4, 2:8.2.2434-1ubuntu1.2, 2:8.2.2434-3ubuntu3.1
vim (Red Hat package) - update to 8.0.1763-15.el8
vim-X11 - update to 8.0.1763-16.0.1
vim-common - update to 8.0.1763-16.0.1
vim-enhanced - update to 8.0.1763-16.0.1
vim-minimal - update to 8.0.1763-16.0.1
vim-filesystem - update to 8.0.1763-16.0.1
Tanzu Greenplum for Kubernetes - update to 2.0.0
Isolation Segment - addressed in versions 2.7.26, 2.8.20, 2.9.14, 2.10.6
VMware Tanzu Application Service for VMs - addressed in versions 2.7.27, 2.8.21, 2.9.15, 2.10.7
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.9.12, 2.10.3
Quay - update to 3.3.3
vim-runtime (Ubuntu package) - addressed in versions 2:7.4.1689-3ubuntu1.5, 2:8.0.1453-1ubuntu1.4
vim-common (Ubuntu package) - addressed in versions 2:7.4.1689-3ubuntu1.5, 2:8.0.1453-1ubuntu1.4
vim (Ubuntu package) - addressed in versions 2:7.4.1689-3ubuntu1.5, 2:8.0.1453-1ubuntu1.4, 2:8.0.1453-1ubuntu1.7, 2:8.1.2269-1ubuntu5.4, 2:8.2.2434-1ubuntu1.2, 2:8.2.2434-3ubuntu3.1
vim (Red Hat package) - update to 8.0.1763-15.el8
vim-X11 - update to 8.0.1763-16.0.1
vim-common - update to 8.0.1763-16.0.1
vim-enhanced - update to 8.0.1763-16.0.1
vim-minimal - update to 8.0.1763-16.0.1
vim-filesystem - update to 8.0.1763-16.0.1
External References
Related Security Bulletins
- OS Command Injection in Vim Vim
- OpenSUSE Linux update for vim
- Red Hat Enterprise Linux 8 update for vim
- Multiple vulnerabilities in VMware Products
- Amazon Linux AMI update for vim
- Multiple vulnerabilities in Red Hat OpenShift Container Storage
- Multiple vulnerabilities in Red Hat Quay
- Amazon Linux AMI update for vim
- Ubuntu update for vim
- Multiple vulnerabilities in Red Hat Service Telemetry Framework
- Anolis OS update for vim
- Ubuntu update for vim