CVE-2017-17087

MEDIUM

Vim <8.0.1263 - Info Disclosure

Title source: llm

Description

fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.

Scores

CVSS v3 5.5
EPSS 0.0016
EPSS Percentile 36.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-668
Status draft

Affected Products (5)

vim/vim < 8.0.1263
debian/debian_linux
debian/debian_linux
canonical/ubuntu_linux
canonical/ubuntu_linux

Timeline

Published Dec 01, 2017
Tracked Since Feb 18, 2026