Submitted by KeesCook on Wed, 2007-05-23 00:52.
usn
Referenced CVEs:
CVE-2007-2438
Description:
===========================================================
Ubuntu Security Notice USN-463-1 May 22, 2007
vim vulnerability
CVE-2007-2438
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.10
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.10:
vim 1:7.0-035+1ubuntu5.1
Ubuntu 7.04:
vim 1:7.0-164+1ubuntu7.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Tomas Golembiovsky discovered that some vim commands were accidentally
allowed in modelines. By tricking a user into opening a specially
crafted file in vim, an attacker could execute arbitrary code with user
privileges.


