ZeroHour

CVE-2016-1248

CVSS 3.0
7.8 high
EPSS
25%p98
Published
()
Modified
Description

vim before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execution of arbitrary code if a file with a specially crafted modeline is opened.

Vendors
vimdebian
Products
vim, debian linux
Weakness
CWE-20
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.