Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
vim 6.3 before 6.3.082, with modelines enabled, allows external user-assisted attackers to execute arbitrary commands via shell metacharacters in the (1) glob or (2) expand commands of a foldexpr expression for calculating fold levels.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Vim modelines 任意命令执行漏洞
Vulnerability Description
vim是一个UNIX高级文本编辑器。 vim 6.3.082之前的6.3版本存在任意命名执行漏洞。在启用modelines时,可让需要外部用户协助的攻击者通过(1) glob中的shell元数据字符或(2)用于计算折叠层数的foldexpr表达式的扩展命令来执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A