PublicDateAtUSN: 2020-05-28 14:15:00 UTC Candidate: CVE-2019-20807 PublicDate: 2020-05-28 14:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20807 https://github.com/vim/vim/releases/tag/v8.1.0881 https://ubuntu.com/security/notices/USN-4582-1 https://ubuntu.com/security/notices/USN-5147-1 Description: In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua). Ubuntu-Description: Notes: Mitigation: Bugs: Priority: low Discovered-by: Assigned-to: sespiros CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L [5.3 MEDIUM] Patches_vim: upstream: https://github.com/vim/vim/commit/8c62a08faf89663e5633dc5036cd8695c80f1075 upstream: https://github.com/vim/vim/commit/54d6fe5e60c0c488a424c078963ead40ae7dc397 upstream_vim: released (2:8.1.2136-1) precise/esm_vim: ignored (end of ESM support, was needed) trusty_vim: ignored (out of standard support) trusty/esm_vim: released (2:7.4.052-1ubuntu3.1+esm4) xenial_vim: released (2:7.4.1689-3ubuntu1.5) esm-infra/xenial_vim: released (2:7.4.1689-3ubuntu1.5) bionic_vim: released (2:8.0.1453-1ubuntu1.4) eoan_vim: ignored (reached end-of-life) focal_vim: not-affected (2:8.1.2269-1ubuntu5) groovy_vim: not-affected (2:8.1.2269-1ubuntu5) hirsute_vim: not-affected (2:8.1.2269-1ubuntu5) impish_vim: not-affected (2:8.1.2269-1ubuntu5) jammy_vim: not-affected (2:8.1.2269-1ubuntu5) devel_vim: not-affected (2:8.1.2269-1ubuntu5)