Skip to navigation

Security Advisory Moderate: vim security update

Advisory: RHSA-2007:0346-3
Type: Security Advisory
Severity: Moderate
Issued on: 2007-05-09
Last updated on: 2007-05-09
Affected Products: Red Hat Enterprise Linux (v. 5 server)
Red Hat Enterprise Linux Desktop (v. 5 client)
CVEs (cve.mitre.org): CVE-2007-2438

Details

Updated vim packages that fix a security issue are now available for Red
Hat Enterprise Linux 5.

This update has been rated as having moderate security impact by the Red Hat
Security Response Team.

VIM (VIsual editor iMproved) is a version of the vi editor.

An arbitrary command execution flaw was found in the way VIM processes
modelines. If a user with modelines enabled opened a text file containing
a carefully crafted modeline, arbitrary commands could be executed as the user
running VIM. (CVE-2007-2438)

Users of VIM are advised to upgrade to these updated packages, which
resolve this issue.

Please note: this issue did not affect VIM as distributed with Red Hat
Enterprise Linux 2.1, 3, or 4.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

Red Hat Enterprise Linux (v. 5 server)

SRPMS:
vim-7.0.109-3.el5.3.src.rpm
File outdated by:  RHBA-2013:0066
    MD5: e057a4d34a4a8560939b9bb588517420
 
IA-32:
vim-X11-7.0.109-3.el5.3.i386.rpm
File outdated by:  RHBA-2013:0066
    MD5: 4a3ea5327008913ecade2dabe0337de7
vim-common-7.0.109-3.el5.3.i386.rpm
File outdated by:  RHBA-2013:0066
    MD5: d9589f3dcbe58f3f355a15405915f939
vim-enhanced-7.0.109-3.el5.3.i386.rpm
File outdated by:  RHBA-2013:0066
    MD5: e1a19e0a474ff74a7546ac83a7905f5c
vim-minimal-7.0.109-3.el5.3.i386.rpm
File outdated by:  RHBA-2013:0066
    MD5: 6539ac943dbf36d8cdd973363bb8b5ba
 
IA-64:
vim-X11-7.0.109-3.el5.3.ia64.rpm
File outdated by:  RHBA-2013:0066
    MD5: 6a019342604776e1a9266ea628292c6b
vim-common-7.0.109-3.el5.3.ia64.rpm
File outdated by:  RHBA-2013:0066
    MD5: 77b51bd7442889406418c7bfb2a97942
vim-enhanced-7.0.109-3.el5.3.ia64.rpm
File outdated by:  RHBA-2013:0066
    MD5: 0852cd42e83dc460d49d64c454315e63
vim-minimal-7.0.109-3.el5.3.ia64.rpm
File outdated by:  RHBA-2013:0066
    MD5: e94013ed5136148fc4022e217350e198
 
PPC:
vim-X11-7.0.109-3.el5.3.ppc.rpm
File outdated by:  RHBA-2013:0066
    MD5: d1e6aa03f74f9a8bbd1f30c80aaba5fd
vim-common-7.0.109-3.el5.3.ppc.rpm
File outdated by:  RHBA-2013:0066
    MD5: 2621bb3dfbef1b8449f61082ecdd6cc8
vim-enhanced-7.0.109-3.el5.3.ppc.rpm
File outdated by:  RHBA-2013:0066
    MD5: e58650f6b7015ee74c018b5e3933d5a2
vim-minimal-7.0.109-3.el5.3.ppc.rpm
File outdated by:  RHBA-2013:0066
    MD5: 76491ca22289c0780d74c0cb98b0b2c6
 
s390x:
vim-X11-7.0.109-3.el5.3.s390x.rpm
File outdated by:  RHBA-2013:0066
    MD5: e5a6e15a237641bd9a49b56b128409d6
vim-common-7.0.109-3.el5.3.s390x.rpm
File outdated by:  RHBA-2013:0066
    MD5: 1fc67cbb34143778972e0756c6b45cc7
vim-enhanced-7.0.109-3.el5.3.s390x.rpm
File outdated by:  RHBA-2013:0066
    MD5: 0dd61a9d9709c3e252439a4b5bb386f7
vim-minimal-7.0.109-3.el5.3.s390x.rpm
File outdated by:  RHBA-2013:0066
    MD5: 39d600c984782b2b7399c2a73c64c33a
 
x86_64:
vim-X11-7.0.109-3.el5.3.x86_64.rpm
File outdated by:  RHBA-2013:0066
    MD5: ee97948f2545f7e0a37b33fb0bde8f11
vim-common-7.0.109-3.el5.3.x86_64.rpm
File outdated by:  RHBA-2013:0066
    MD5: 986ee1a67308fcb05ea90afa85eb14b4
vim-enhanced-7.0.109-3.el5.3.x86_64.rpm
File outdated by:  RHBA-2013:0066
    MD5: 49aa8c77bb180de51539cb7d0f5d635d
vim-minimal-7.0.109-3.el5.3.x86_64.rpm
File outdated by:  RHBA-2013:0066
    MD5: da6d10a02e1cf4121095ab6e9544f4db
 
Red Hat Enterprise Linux Desktop (v. 5 client)

SRPMS:
vim-7.0.109-3.el5.3.src.rpm
File outdated by:  RHBA-2013:0066
    MD5: e057a4d34a4a8560939b9bb588517420
 
IA-32:
vim-X11-7.0.109-3.el5.3.i386.rpm
File outdated by:  RHBA-2013:0066
    MD5: 4a3ea5327008913ecade2dabe0337de7
vim-common-7.0.109-3.el5.3.i386.rpm
File outdated by:  RHBA-2013:0066
    MD5: d9589f3dcbe58f3f355a15405915f939
vim-enhanced-7.0.109-3.el5.3.i386.rpm
File outdated by:  RHBA-2013:0066
    MD5: e1a19e0a474ff74a7546ac83a7905f5c
vim-minimal-7.0.109-3.el5.3.i386.rpm
File outdated by:  RHBA-2013:0066
    MD5: 6539ac943dbf36d8cdd973363bb8b5ba
 
x86_64:
vim-X11-7.0.109-3.el5.3.x86_64.rpm
File outdated by:  RHBA-2013:0066
    MD5: ee97948f2545f7e0a37b33fb0bde8f11
vim-common-7.0.109-3.el5.3.x86_64.rpm
File outdated by:  RHBA-2013:0066
    MD5: 986ee1a67308fcb05ea90afa85eb14b4
vim-enhanced-7.0.109-3.el5.3.x86_64.rpm
File outdated by:  RHBA-2013:0066
    MD5: 49aa8c77bb180de51539cb7d0f5d635d
vim-minimal-7.0.109-3.el5.3.x86_64.rpm
File outdated by:  RHBA-2013:0066
    MD5: da6d10a02e1cf4121095ab6e9544f4db
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

238259 - CVE-2007-2438 vim-7 modeline security issue


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/