Linux Command-Line Editors Vulnerable to High-Severity Bug -- vim, neovim 06-11-2019, 06:47 PM
#1
Quote:A high-severity bug impacting two popular command-line text editing applications, Vim and Neovim, allow remote attackers to execute arbitrary OS commands. Security researcher Armin Razmjou warned that exploiting the bug is as easy as tricking a target into clicking on a specially crafted text file in either editor.
...
Razmjou outlined his research and created a proof-of-concept (PoC) attack demonstrating how an adversary can compromise a Linux system via Vim or Neovim. He said Vim versions before 8.1.1365 and Neovim before 0.3.6 are vulnerable to arbitrary code execution.
Jesus Christ. Many servers have some patching to do.
Link: https://threatpost.com/linux-command-lin...ug/145569/