The vendor explicitly states that these products are not affected by this CVE.
- vim-X11 as a component of Red Hat Enterprise Linux 10
- vim-common as a component of Red Hat Enterprise Linux 10
- vim-data as a component of Red Hat Enterprise Linux 10
- vim-enhanced as a component of Red Hat Enterprise Linux 10
- vim-filesystem as a component of Red Hat Enterprise Linux 10
- vim-minimal as a component of Red Hat Enterprise Linux 10
- vim.src as a component of Red Hat Enterprise Linux 10
- xxd as a component of Red Hat Enterprise Linux 10
- vim-X11 as a component of Red Hat Enterprise Linux 6
- vim-common as a component of Red Hat Enterprise Linux 6
- vim-enhanced as a component of Red Hat Enterprise Linux 6
- vim-filesystem as a component of Red Hat Enterprise Linux 6
- Summary
- A flaw was found in Vim, specifically within the netrw plugin. A local user could exploit a Vimscript code injection vulnerability by attempting to delete a specially crafted local file from the browser. This crafted filename, containing a bar character, could be interpolated into an Ex command, allowing for the execution of arbitrary Vimscript, including shell commands. This could lead to arbitrary code execution on the affected system.
- Remediation
- No remediation text is recorded.
