CVE-2017-1000382 PUBLISHED

VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the vi binary.

EPSS 0.09% · 26.0th percentile

Risk Scores

EPSS Score
0.09%
26.0th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSvim2:7.4.1689-3ubuntu1.3, 2:7.4.1689-3ubuntu1.4, 2:7.4.1689-3ubuntu1.5
Ubuntu:Pro:14.04:LTSvim2:7.4.052-1ubuntu3.1+esm18, 2:7.4.000-1ubuntu2, 2:7.4.052-1ubuntu1
Ubuntu:Pro:18.04:LTSvim0, 2:8.0.0197-4ubuntu5, 2:8.0.1144-1ubuntu1

Timeline

References

Open in Interactive Console →