Secunia Logo  
 
CVE Reference: CVE-2008-4677
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-4677

Description:
autoload/netrw.vim (aka the Netrw Plugin) 109, 131, and other versions before 133k for Vim 7.1.266, other 7.1 versions, and 7.2 stores credentials for an FTP session, and sends those credentials when attempting to establish subsequent FTP sessions to servers on different hosts, which allows remote FTP servers to obtain sensitive information in opportunistic circumstances by logging usernames and passwords. NOTE: the upstream vendor disputes a vector involving different ports on the same host, stating "I'm assuming that they're using the same id and password on that unchanged hostname, deliberately."

CVE Status:
Candidate

References:

SAID
  Secunia Advisory: SA31464

MLIST
  http://www.openwall.com/lists/oss-security/2008/10/06/4
  http://www.openwall.com/lists/oss-security/2008/10/16/2
  http://www.openwall.com/lists/oss-security/2008/10/20/2
  http://groups.google.com/group/vim_dev/browse_thread/thread/2f6fad581a037971/a5fcf4c4981d34e6?show_docid=a5fcf4c4981d34e6

MISC
  http://www.rdancer.org/vulnerablevim-netrw-credentials-dis.html

CONFIRM


Return to the previous page.