CVE-2016-1248

Publication date 23 November 2016

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

7.8 · High

Score breakdown

vim before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execution of arbitrary code if a file with a specially crafted modeline is opened.

From the Ubuntu Security Team

Florian Larysch discovered that the Vim text editor did not properly validate values for the 'filetype', 'syntax', and 'keymap' options. An attacker could trick a user into opening a file with specially crafted modelines and possibly execute arbitrary code with the user's privileges.

Status

Package Ubuntu Release Status
neovim 17.04 zesty
Not affected
16.10 yakkety Not in release
16.04 LTS xenial Not in release
14.04 LTS trusty Not in release
12.04 LTS precise Not in release
vim 17.04 zesty
Not affected
16.10 yakkety
Fixed 2:7.4.1829-1ubuntu2.1
16.04 LTS xenial
Fixed 2:7.4.1689-3ubuntu1.2
14.04 LTS trusty
Fixed 2:7.4.052-1ubuntu3.1
12.04 LTS precise
Fixed 2:7.3.429-2ubuntu2.2

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
neovim
vim

Severity score breakdown

Parameter Value
Base score 7.8 · High
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H