CVE-2009-0316

Description

Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983), as demonstrated by an erroneous search path for plugin/bike.vim in bicyclerepair.

Risk Information

Base Score
8.4
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.211

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2009-0316 are affected in Vim 1.0Windows
Vulnerabilities CVE-2009-0316 are affected in Vim 1.22Windows
Vulnerabilities CVE-2008-4101,CVE-2009-0316 are affected in Vim 3.0Windows
Vulnerabilities CVE-2008-4101,CVE-2009-0316 are affected in Vim 4.0Windows
Multiple Vulnerabilities are affected in Vim 5.0Windows
Multiple Vulnerabilities are affected in Vim 5.1Windows
Multiple Vulnerabilities are affected in Vim 5.2Windows
Multiple Vulnerabilities are affected in Vim 5.3Windows
Multiple Vulnerabilities are affected in Vim 5.4Windows
Multiple Vulnerabilities are affected in Vim 5.5Windows
Multiple Vulnerabilities are affected in Vim 5.6Windows
Multiple Vulnerabilities are affected in Vim 5.7Windows
Multiple Vulnerabilities are affected in Vim 5.8Windows
Multiple Vulnerabilities are affected in Vim 6.0Windows
Multiple Vulnerabilities are affected in Vim 6.1Windows
Multiple Vulnerabilities are affected in Vim 6.2Windows
Multiple Vulnerabilities are affected in Vim 6.3Windows
Multiple Vulnerabilities are affected in Vim 6.4Windows
Multiple Vulnerabilities are affected in Vim 7.0Windows
Multiple Vulnerabilities are affected in Vim 7.1Windows
Vulnerabilities CVE-2008-3074,CVE-2008-3075,CVE-2008-4101,CVE-2009-0316 are affected in Vim 7.2Windows
SUSE-SU-2022:4619-1(SUSE Linux Enterprise Server 12-SP5 ) gvim-9.0.0814-17.9.1.x86_64.rpmLinux
SUSE-SU-2022:4619-1(SUSE Linux Enterprise Server 12-SP5 ) gvim-debuginfo-9.0.0814-17.9.1.x86_64.rpmLinux
SUSE-SU-2022:4619-1(SUSE Linux Enterprise Server 12-SP5 ) vim-data-9.0.0814-17.9.1.noarch.rpmLinux
SUSE-SU-2022:4619-1(SUSE Linux Enterprise Server 12-SP5 ) vim-data-common-9.0.0814-17.9.1.noarch.rpmLinux
SUSE-SU-2022:4619-1(SUSE Linux Enterprise Server 12-SP5 ) vim-debugsource-9.0.0814-17.9.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234