Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Vim: Arbitrary Ex Command Execution in C Omni-Completion
Vulnerability Description
Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using an insufficiently escaped typeref: or typename: value from a tags file, allowing an unterminated collection followed by a command separator to execute arbitrary Ex and operating-system commands when a user invokes C omni-completion with CTRL-X CTRL-O on a member access whose type is resolved from that tags file. This issue is fixed in version 9.2.0845.
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
Vim 软件供应链问题漏洞
Vulnerability Description
Vim是组织开源的一款高效的文本编辑器。 Vim 9.2.0845之前版本存在安全漏洞,该漏洞源于runtime/autoload/ccomplete.vim中的StructMembers()函数使用未充分转义的typeref或typename值构造并执行vimgrep命令,可能导致用户调用C omni-completion时执行任意Ex和操作系统命令。
CVSS Information
N/A
Vulnerability Type
N/A