CVE-2019-20807

In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*

Configuration 5 (hide)

OR cpe:2.3:o:apple:mac_os_x:10.13.6:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.14.6:*:*:*:*:*:*:*

Configuration 6 (hide)

OR cpe:2.3:a:starwindsoftware:command_center:2:build_6003:*:*:*:*:*:*
cpe:2.3:a:starwindsoftware:san_\&_nas:1.0:update_1:*:*:*:*:*:*

Information

Published : 2020-05-28 07:15

Updated : 2022-09-01 08:14


NVD link : CVE-2019-20807

Mitre link : CVE-2019-20807


JSON object : View

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Advertisement

dedicated server usa

Products Affected

vim

  • vim

starwindsoftware

  • command_center
  • san_\&_nas

canonical

  • ubuntu_linux

opensuse

  • leap

debian

  • debian_linux

apple

  • mac_os_x