CVE-2008-2712

vim < 6.4 - Remote Code Execution via Unsanitized Inputs in Vim Scripts

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-2712. PoCs published by Jan Minar.

AI-analyzed exploit summary The provided text describes multiple command-execution vulnerabilities in Vim 7.1.298 due to insufficient sanitization of user-supplied data. It references external sources for exploit binaries but does not contain actual exploit code.

Description

Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properly sanitize inputs before invoking the execute or system functions, as demonstrated using (1) filetype.vim, (3) xpm.vim, (4) gzip_vim, and (5) netrw. NOTE: the originally reported version was 7.1.314, but the researcher actually found this set of issues in 7.1.298. NOTE: the zipplugin issue (originally vector 2 in this identifier) has been subsumed by CVE-2008-3075.

Exploits (1)

exploitdb WRITEUP
by Jan Minar · textlocallinux
https://www.exploit-db.com/exploits/31911

The provided text describes multiple command-execution vulnerabilities in Vim 7.1.298 due to insufficient sanitization of user-supplied data. It references external sources for exploit binaries but does not contain actual exploit code.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Vim 7.1.298
No auth needed
Prerequisites: User interaction to open a malicious file in Vim
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (40)

Core 40
Core References
Third Party Advisory x_refsource_confirm
http://www.vmware.com/security/advisories/VMSA-2009-0004.html
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2008-0618.html
Broken Link x_refsource_misc
http://www.rdancer.org/vulnerablevim.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-712-1
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31681
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/43083
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32858
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33410
Mailing List, Third Party Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2008-0580.html
Third Party Advisory x_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2009-001.htm
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34418
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0904
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0033
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/495319/100/0/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/493353/100/0/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/502322/100/0/threaded
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2008/06/16/2
Mailing List, Third Party Advisory mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=121494431426308&w=2
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1851/references
Third Party Advisory x_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2008-457.htm
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30731
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32222
Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT4077
Broken Link x_refsource_confirm
https://issues.rpath.com/browse/RPL-2622
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3951
Third Party Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2008:236
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2780
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2008/10/15/1
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32864
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1020293
Mailing List, Third Party Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html
Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT3216
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/29715
Third Party Advisory x_refsource_confirm
http://wiki.rpath.com/Advisories:rPSA-2008-0247
Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2008-0617.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/493352/100/0/threaded

Scores

EPSS 0.1504
EPSS Percentile 96.3%

Details

CWE
CWE-20
Status published
Products (5)
canonical/ubuntu_linux 6.06
canonical/ubuntu_linux 7.10
canonical/ubuntu_linux 8.04
canonical/ubuntu_linux 8.10
vim/vim < 6.4
Published Jun 16, 2008
Tracked Since Feb 18, 2026