CVE-2017-17087
vim - security update
5.5
MEDIUM
CVSS 3.1
EPSS 0.36%
描述
fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.
如何修補 CVE-2017-17087
要修補 CVE-2017-17087,請將受影響套件升級到下列已修補版本。
- —升級至 2:8.0.1401-1 或更新版本
- —升級至 2:8.0.0197-4+deb9u4 或更新版本
CVE-2017-17087 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 2:8.0.1401-1
- from 0, < 2:8.0.0197-4+deb9u4
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |