vim 6.3 before 6.3.082, with modelines enabled, allows external user-assisted attackers to execute arbitrary commands via shell metacharacters in the (1) glob or (2) expand commands of a foldexpr expression for calculating fold levels.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-07-25 21:00
Updated : 2017-10-10 18:30
NVD link : CVE-2005-2368
Mitre link : CVE-2005-2368
JSON object : View
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Products Affected
vim_development_group
- vim