>> Vim Modelines Option Local Command Execution Vulnerability
Title : Vim Modelines Option Local Command Execution Vulnerability VUPEN ID : VUPEN/ADV-2005-1216 CVE ID : CVE-2005-2368 CWE ID : CWE-
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2005-07-26
Technical Description
A vulnerability was identified in Vim, which may be exploited by local attackers to execute arbitrary commands. This flaw is due to an error when processing specially crafted modelines containing "glob()" or "expand()" calls, which may be exploited by local attackers to execute arbitrary commands by convincing a user to open a malicious file.