Welcome to Centmin Mod Community
Become a Member

Security Your Linux Can Get Hacked Just by Opening a File in Vim or Neovim Editor

Discussion in 'CentOS, Redhat & Oracle Linux News' started by pamamolf, Jun 11, 2019.

  1. pamamolf

    pamamolf Premium Member Premium Member

    3,304
    318
    83
    May 31, 2014
    Ratings:
    +588
    Local Time:
    3:29 PM
    Nginx-1.13.x
    MariaDB 10.1.x
    Hello

    Product: Vim < 8.1.1365, Neovim < 0.3.6
    Type: Arbitrary Code Execution
    CVE: CVE-2019-12735
    Date: 2019-06-04
    Author: Arminius (@rawsec)

    Summary
    Vim before 8.1.1365 and Neovim before 0.3.6 are vulnerable to arbitrary code execution via modelines by opening a specially crafted text file.

    Check it out :)

    numirias/security
     
    • Like Like x 1
    • Informative Informative x 1
  2. eva2000

    eva2000 Administrator Staff Member

    40,276
    8,926
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +13,746
    Local Time:
    10:29 PM
    Nginx 1.15.x
    MariaDB 5.5/10.x
    thanks for heads up i use nano heh

    For RedHat/CentOS
    all under investigation right now
    CentOS 7 for Centmin Mod installs vim-minimal yum package right now but we need to look not at version number but the minor version increment and rpm changelog once an update is out for Redhat/CentOS
    Code (Text):
    yum list installed -q | grep vim
    vim-minimal.x86_64              2:7.4.160-5.el7                  @base
    

    Code (Text):
    rpm -qa vim-minimal
    vim-minimal-7.4.160-5.el7.x86_64
    
     
    • Informative Informative x 1
  3. BamaStangGuy

    BamaStangGuy Active Member

    568
    170
    43
    May 25, 2014
    Ratings:
    +231
    Local Time:
    7:29 AM
    Nano user as well.
     
  4. Itworx4me

    Itworx4me Premium Member Premium Member

    173
    18
    18
    Mar 14, 2017
    Ratings:
    +28
    Local Time:
    5:29 AM
    Nginx 1.17.X
    MariaDB 10.3.X
     
..