CVE-2008-4101
18.09.2008, 17:59
Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) followed by a command, or execute arbitrary Ex commands by entering an argument after a (2) "Ctrl-]" (control close-square-bracket) or (3) "g]" (g close-square-bracket) keystroke sequence, a different issue than CVE-2008-2712.Enginsight
| Vendor | Product | Version |
|---|---|---|
| vim | vim | 𝑥 ≤ 7.2 |
| vim | vim | 3.0 |
| vim | vim | 4.0 |
| vim | vim | 5.0 |
| vim | vim | 5.1 |
| vim | vim | 5.2 |
| vim | vim | 5.3 |
| vim | vim | 5.4 |
| vim | vim | 5.5 |
| vim | vim | 5.6 |
| vim | vim | 5.7 |
| vim | vim | 5.8 |
| vim | vim | 6.0 |
| vim | vim | 6.1 |
| vim | vim | 6.2 |
| vim | vim | 6.3 |
| vim | vim | 6.4 |
| vim | vim | 7.0 |
| vim | vim | 7.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References