glvd logo
glvd logo
Garden Linux Vulnerability Database
CVE Description

"autoload/netrw.vim (aka the Netrw Plugin) 109, 131, and other versions before 133k for Vim 7.1.266, other 7.1 versions, and 7.2 stores credentials for an FTP session, and sends those credentials when attempting to establish subsequent FTP sessions to servers on different hosts, which allows remote FTP servers to obtain sensitive information in opportunistic circumstances by logging usernames and passwords. NOTE: the upstream vendor disputes a vector involving different ports on the same host, stating \"I'm assuming that they're using the same id and password on that unchanged hostname, deliberately.\""

Metadata

Vulnerability Status Published Date Modified Date Ingested Date
Deferred 2008-10-22T18:00:00.910 2025-04-09T00:30:58.490 2025-04-09 00:30:58.49+00

CVSS Scores

CVSS Version Base Score DEB CVSS Severity Vector String
2 4.3 UNIMPORTANT AV:N/AC:M/Au:N/C:P/I:N/A:N

Affected Linux Images

Distro Version Source Package Package Version Is Vulnerable Is fixed in Version
gardenlinux kvm-cilium-k3s-1605.0-490ed850 vim 2:9.1.0496-1+b1 true
gardenlinux kvm-gardener-1605.0-490ed850 vim 2:9.1.0496-1+b1 true
gardenlinux metal-cilium-k3s-osc-vhost-1605.0-490ed850 vim 2:9.1.0496-1+b1 true
gardenlinux metal-cilium-k3s-osc-1605.0-490ed850 vim 2:9.1.0496-1+b1 true
gardenlinux kvm-cilium-k3s-1721.0-9802b525 vim 2:9.1.0861-1 true
gardenlinux kvm-gardener-1721.0-9802b525 vim 2:9.1.0861-1 true
gardenlinux metal-cilium-k3s-osc-ucode-vhost-1721.0-9802b525 vim 2:9.1.0861-1 true
gardenlinux metal-cilium-k3s-osc-ucode-1721.0-9802b525 vim 2:9.1.0861-1 true
debian_linux 13 vim 2:9.1.1230-2 true
debian_linux 12 vim 2:9.0.1378-2+deb12u2 true
gardenlinux metal-cilium-k3s-osc-router-ucode-1721.0-9802b525 vim 2:9.1.0861-1 true
gardenlinux kvm-cilium-k3s-1862.0-6be879c6 vim 2:9.1.1230-1 true
gardenlinux kvm-gardener-1862.0-6be879c6 vim 2:9.1.1230-1 true
gardenlinux pt-gardener-nvgpu-1862.0-6be879c6 vim 2:9.1.1230-1 true
gardenlinux metal-cilium-k3s-osc-ucode-vhost-1862.0-6be879c6 vim 2:9.1.1230-1 true
gardenlinux metal-cilium-k3s-osc-ucode-1862.0-6be879c6 vim 2:9.1.1230-1 true
gardenlinux metal-cilium-k3s-osc-router-ucode-1862.0-6be879c6 vim 2:9.1.1230-1 true
debian_linux 14 vim 2:9.1.2103-1 true