Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2008-4101

Publication date 18 September 2008

Last updated 24 July 2024


Ubuntu priority

Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) followed by a command, or execute arbitrary Ex commands by entering an argument after a (2) "Ctrl-]" (control close-square-bracket) or (3) "g]" (g close-square-bracket) keystroke sequence, a different issue than CVE-2008-2712.

Status

Package Ubuntu Release Status
vim 8.10 intrepid
Fixed 1:7.1.314-3ubuntu3.1
8.04 LTS hardy
Fixed 1:7.1-138+1ubuntu3.1
7.10 gutsy
Fixed 1:7.1-056+2ubuntu2.1
7.04 feisty Ignored
6.06 LTS dapper
Fixed 1:6.4-006+2ubuntu6.2

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
vim

References

Related Ubuntu Security Notices (USN)

    • USN-712-1
    • Vim vulnerabilities
    • 27 January 2009

Other references