Vulnerability Description
fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vim | Vim | < 8.0.1263 |
| Debian | Debian Linux | 8.0 |
| Canonical | Ubuntu Linux | 16.04 |
Related Weaknesses (CWE)
References
- http://openwall.com/lists/oss-security/2017/11/27/2Mailing List
- http://security.cucumberlinux.com/security/details.php?id=166Issue TrackingThird Party Advisory
- https://github.com/vim/vim/commit/5a73e0ca54c77e067c3b12ea6f35e3e8681e8cf8PatchThird Party Advisory
- https://groups.google.com/d/msg/vim_dev/sRT9BtjLWMk/BRtSXNU4BwAJIssue TrackingMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/08/msg00003.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/01/msg00003.htmlMailing ListThird Party Advisory
- https://usn.ubuntu.com/4582-1/Third Party Advisory
- http://openwall.com/lists/oss-security/2017/11/27/2Mailing List
- http://security.cucumberlinux.com/security/details.php?id=166Issue TrackingThird Party Advisory
- https://github.com/vim/vim/commit/5a73e0ca54c77e067c3b12ea6f35e3e8681e8cf8PatchThird Party Advisory
- https://groups.google.com/d/msg/vim_dev/sRT9BtjLWMk/BRtSXNU4BwAJIssue TrackingMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/08/msg00003.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/01/msg00003.htmlMailing ListThird Party Advisory
- https://usn.ubuntu.com/4582-1/Third Party Advisory
FAQ
What is CVE-2017-17087?
CVE-2017-17087 is a vulnerability with a CVSS score of 5.5 (MEDIUM). fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users...
How severe is CVE-2017-17087?
CVE-2017-17087 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-17087?
Check the references section above for vendor advisories and patch information. Affected products include: Vim Vim, Debian Debian Linux, Canonical Ubuntu Linux.