The vendor explicitly identifies these products as affected by this CVE.
- vim-X11 as a component of Red Hat Enterprise Linux 6
- vim-common as a component of Red Hat Enterprise Linux 6
- vim-enhanced as a component of Red Hat Enterprise Linux 6
- vim-filesystem as a component of Red Hat Enterprise Linux 6
- vim-minimal as a component of Red Hat Enterprise Linux 6
- vim.src as a component of Red Hat Enterprise Linux 6
- Summary
- A flaw was found in Vim, an open-source command-line text editor. The Python omni-completion feature executes reconstructed function and class definitions from the current buffer. A remote attacker can exploit this by crafting a hostile buffer, leading to the execution of attacker-controlled Python expressions during omni-completion. This vulnerability can result in arbitrary code execution.
- Remediation
- Out of support scope
