[Full-disclosure] Vim: Arbitrary Code Execution in Commands: K, Control-], g]

2008-08-22 Thread Jan Minář
Vim: Arbitrary Code Execution in Commands: K, Control-], g] 1. SUMMARY Product : Vim -- Vi IMproved Versions : 3.0--current, possibly older Impact : Arbitrary code execution Wherefrom: Local Original : http://www.rdancer.org/vulnerablevim-K.html Insufficient sanitization can lead to Vim execu

[Full-disclosure] Vim: Netrw: FTP User Name and Password Disclosure

2008-08-12 Thread Jan Minář
Vim: Netrw: FTP User Name and Password Disclosure 1. SUMMARY Product : Vim -- Vi IMproved Versions : Tested with Vim 7.1.266, 7.2, autoload/netrw.vim v131, v109 Impact : Credentials disclosure Wherefrom: Remote Original : http://www.rdancer.org/vulnerablevim-netrw-credentials-dis.html The Vim

[Full-disclosure] Vim: Unfixed Vulnerabilities in Tar Plugin Version 20

2008-08-08 Thread Jan Minář
Vim: Unfixed Vulnerabilities in Tar Plugin Version 20 1. SUMMARY Product : Vim -- Vi IMproved Version : Vim >= 7.0 (possibly older), present in 7.2c.002 autoload/tar.vim >= 9 (possibly older), present in version 20 Impact : Arbitrary code execution Wherefrom: Local, remote CVE

[Full-disclosure] Vim 7.2c.002 Fixes Arbitrary Command Execution when Handling Tar Archives

2008-08-08 Thread Jan Minář
Vim 7.2c.002 Fixes Arbitrary Command Execution when Handling Tar Archives 1. SUMMARY Product : Vim -- Vi IMproved Version : Vim >= 7.0 (possibly older), fixed in 7.2c.002 autoload/tar.vim version >= 9 (possibly older) Impact : Arbitrary code execution Wherefrom: Local, remote Origi

Re: [Full-disclosure] Vim: Insecure Temporary File Creation During Build: Arbitrary Code Execution

2008-07-26 Thread Jan Minář
On Fri, Jul 25, 2008 at 4:57 PM, Steven M. Christey <[EMAIL PROTECTED]> wrote: > > On Fri, 25 Jul 2008, [UTF-8] Jan MináÅ^Y wrote: > >> > The commands do not have to be written there between (1) and (2), they >> > can be in the file long before the ./configure was started -- just >> > because the s

Re: [Full-disclosure] Vim: Insecure Temporary File Creation During Build: Arbitrary Code Execution

2008-07-24 Thread Jan Minář
2008/7/25 Robert Buchholz <[EMAIL PROTECTED]>: > On Friday 18 July 2008, Jan Minář wrote: > ... >> 3. Vulnerability >> >> During the build process, a temporary file with a predictable name is >> created in the ``/tmp'' directory. This code is run

[Full-disclosure] Vim: Flawed Fix of Arbitrary Code Execution Vulnerability in filetype.vim

2008-07-23 Thread Jan Minář
1. SUMMARY Product : Vim -- Vi IMproved Version : Tested with Vim 7.2b.10, filetype.vim 2008-07-17 Impact : Arbitrary code execution Wherefrom: Local and remote CVE : CVE-2008-2712 Original : http://www.rdancer.org/vulnerablevim-filetype.vim.updated.html http://www.rdancer.org/

[Full-disclosure] Vim: Insecure Temporary File Creation During Build: Arbitrary Code Execution

2008-07-17 Thread Jan Minář
1. Summary Product : Vim -- Vi IMproved Versions : 5.0--current, possibly older; 4.6 and 3.0 not vulnerable Impact : Arbitrary code execution Wherefrom: Local Original : http://www.rdancer.org/vulnerablevim-configure.in.html http://www.rdancer.org/vulnerablevim-configure.in.patch In

[Full-disclosure] Arbitrary code execution in Netrw version 127, Vim 7.2b

2008-07-16 Thread Jan Minář
1. Summary Product : Vim -- Vi IMproved, Netrw Version : Tested with Vim 7.2b, Netrw 127 Impact : Arbitrary code execution Wherefrom: Local, possibly remote Original : http://www.rdancer.org/vulnerablevim-netrw.v5.html http://www.rdancer.org/vulnerablevim-latest.tar.bz2 Lack of san

[Full-disclosure] Vim: Improper Implementation of shellescape()/Arbitrary Code Execution

2008-07-16 Thread Jan Minář
1. Summary Product : Vim -- Vi IMproved Version : >= 7.2a.013; tested with 7.2b Impact : Arbitrary code execution Wherefrom: Local, possibly remote Original : http://www.rdancer.org/vulnerablevim-shellescape.html http://www.rdancer.org/vulnerablevim-latest.tar.bz2 Improper implemen

Re: [Full-disclosure] Collection of Vulnerabilities in Fully Patched Vim 7.1

2008-07-01 Thread Jan Minář
On Sat, Jun 14, 2008 at 2:09 PM, Bram Moolenaar <[EMAIL PROTECTED]> wrote: > > Jan Minar wrote: > >> 1. Summary >> >> Product : Vim -- Vi IMproved >> Version : Tested with 7.1.314 and 6.4 >> Impact : Arbitrary code execution >> Wherefrom: Local and remote >> Original : http://www.rdancer.org/vu

[Full-disclosure] Collection of Vulnerabilities in Fully Patched Vim 7.1

2008-06-13 Thread Jan Minář
1. Summary Product : Vim -- Vi IMproved Version : Tested with 7.1.314 and 6.4 Impact : Arbitrary code execution Wherefrom: Local and remote Original : http://www.rdancer.org/vulnerablevim.html Improper quoting in some parts of Vim written in the Vim Script can lead to arbitrary code execution