CVE-2008-3294

EUVD-2008-3282
src/configure.in in Vim 5.0 through 7.1, when used for a build with Python support, does not ensure that the Makefile-conf temporary file has the intended ownership and permissions, which allows local users to execute arbitrary code by modifying this file during a time window, or by creating it ahead of time with permissions that prevent its modification by configure.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.7 UNKNOWN
LOCAL
HIGH
AV:L/AC:H/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
Affected Products (NVD)
VendorProductVersion
vimvim
5.0
vimvim
5.1
vimvim
5.2
vimvim
5.3
vimvim
5.4
vimvim
5.5
vimvim
5.6
vimvim
5.7
vimvim
5.8
vimvim
6.0
vimvim
6.1
vimvim
6.2
vimvim
6.3
vimvim
6.4
vimvim
7.0
vimvim
7.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
vim
bookworm
2:9.0.1378-2
fixed
bullseye
2:8.2.2434-3+deb11u1
fixed
sid
2:9.1.0777-1
fixed
trixie
2:9.1.0777-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
vim
dapper
not-affected
feisty
not-affected
gutsy
not-affected
hardy
not-affected