Vulnerability Description
In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vim | Vim | < 8.1.0881 |
| Debian | Debian Linux | 9.0 |
| Opensuse | Leap | 15.1 |
| Canonical | Ubuntu Linux | 16.04 |
| Apple | Mac Os X | 10.13.6 |
| Starwindsoftware | Command Center | 2 |
| Starwindsoftware | San \& Nas | 1.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00018.htmlMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2020/Jul/24Mailing ListThird Party Advisory
- https://github.com/vim/vim/commit/8c62a08faf89663e5633dc5036cd8695c80f1075PatchThird Party Advisory
- https://github.com/vim/vim/releases/tag/v8.1.0881Release NotesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/01/msg00003.htmlMailing ListThird Party Advisory
- https://support.apple.com/kb/HT211289Third Party Advisory
- https://usn.ubuntu.com/4582-1/Mailing ListThird Party Advisory
- https://www.starwindsoftware.com/security/sw-20220812-0003/Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00018.htmlMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2020/Jul/24Mailing ListThird Party Advisory
- https://github.com/vim/vim/commit/8c62a08faf89663e5633dc5036cd8695c80f1075PatchThird Party Advisory
- https://github.com/vim/vim/releases/tag/v8.1.0881Release NotesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/01/msg00003.htmlMailing ListThird Party Advisory
- https://support.apple.com/kb/HT211289Third Party Advisory
- https://usn.ubuntu.com/4582-1/Mailing ListThird Party Advisory
FAQ
What is CVE-2019-20807?
CVE-2019-20807 is a vulnerability with a CVSS score of 5.3 (MEDIUM). In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).
How severe is CVE-2019-20807?
CVE-2019-20807 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-20807?
Check the references section above for vendor advisories and patch information. Affected products include: Vim Vim, Debian Debian Linux, Opensuse Leap, Canonical Ubuntu Linux, Apple Mac Os X.