RHSA-2020:4453: vim security update (Moderate)

description-logoDescription

The vulnerabilities in the following products could cause the system to become vulnerable to malicious security attack: vim

Analysis

Vim (Vi IMproved) is an updated and improved version of the vi editor. Security Fix(es): * vim: users can execute arbitrary OS commands via scripting interfaces in the rvim restricted mode (CVE-2019-20807) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section.

affected-products-logoAffected Applications

vim

CVE References

CVE-2019-20807