Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: vim vim-core gvim
Date: Thu, 23 Jan 2003 11:50:36
Message-Id: 20030122114823.BD78933B4D@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200301-13
6 - - --------------------------------------------------------------------
7
8 PACKAGE : vim vim-core gvim
9 SUMMARY : arbitrary code execution
10 DATE : 2003-01-22 11:48 UTC
11 EXPLOIT : remote
12
13 - - --------------------------------------------------------------------
14
15 - From advisory:
16
17 "Opening a specially crafted text file with vim can execute arbitrary shell
18 commands and pass parameters to them."
19
20 Read the full advisory at
21 http://www.guninski.com/vim1.html
22
23 SOLUTION
24
25 It is recommended that all Gentoo Linux users who are running
26 affected versions of app-editors/{vim,vim-core,gvim} upgrade as follows:
27
28 emerge sync
29
30 If you are running app-editos/vim-core upgrade to vim-core-6.1-r4 :
31
32 emerge -u vim-core
33
34 If you are running app-editos/vim upgrade to vim-6.1-r19 :
35
36 emerge -u vim
37
38 If you are running app-editos/gvim upgrade to gvim-6.1-r6 :
39
40 emerge -u gvim
41
42 emerge clean
43
44 - - --------------------------------------------------------------------
45 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
46 rphillips@g.o
47 - - --------------------------------------------------------------------
48 -----BEGIN PGP SIGNATURE-----
49 Version: GnuPG v1.2.1 (GNU/Linux)
50
51 iD8DBQE+LoUAfT7nyhUpoZMRArcGAKCAVB+gvc8+iCjOFR/HYTOmqHdVLACeIoJ1
52 IKN3PiG5ilVLySKq2GKA4/k=
53 =H+Dh
54 -----END PGP SIGNATURE-----