Syntastic Project Syntastic 2.2.0 for Vim

CPE Details

Syntastic Project Syntastic 2.2.0 for Vim
2.2.0
2020-03-12
16h46 +00:00
2020-03-12
16h46 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:syntastic_project:syntastic:2.2.0:*:*:*:*:vim:*:*

Informations

Vendor

syntastic_project

Product

syntastic

Version

2.2.0

Target Software

vim

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2018-11319 2018-05-20 18h00 +00:00 Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potentially the root). This improper handling might be exploited for arbitrary code execution via a malicious gcc plugin, if an attacker has write access to a directory that is a parent of the base directory of the project being checked. NOTE: exploitation is more difficult after 3.8.0 because filename prediction may be needed.
7.5
High