fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.
{ "binaries": [ { "binary_name": "vim", "binary_version": "2:7.4.052-1ubuntu3.1+esm4" }, { "binary_name": "vim-athena", "binary_version": "2:7.4.052-1ubuntu3.1+esm4" }, { "binary_name": "vim-athena-dbgsym", "binary_version": "2:7.4.052-1ubuntu3.1+esm4" }, { "binary_name": "vim-common", "binary_version": "2:7.4.052-1ubuntu3.1+esm4" }, { "binary_name": "vim-common-dbgsym", "binary_version": "2:7.4.052-1ubuntu3.1+esm4" }, { "binary_name": "vim-dbg", "binary_version": "2:7.4.052-1ubuntu3.1+esm4" }, { "binary_name": "vim-dbgsym", "binary_version": "2:7.4.052-1ubuntu3.1+esm4" }, { "binary_name": "vim-doc", "binary_version": "2:7.4.052-1ubuntu3.1+esm4" }, { "binary_name": "vim-gnome", "binary_version": "2:7.4.052-1ubuntu3.1+esm4" }, { "binary_name": "vim-gnome-dbgsym", "binary_version": "2:7.4.052-1ubuntu3.1+esm4" }, { "binary_name": "vim-gtk", "binary_version": "2:7.4.052-1ubuntu3.1+esm4" }, { "binary_name": "vim-gtk-dbgsym", "binary_version": "2:7.4.052-1ubuntu3.1+esm4" }, { "binary_name": "vim-gui-common", "binary_version": "2:7.4.052-1ubuntu3.1+esm4" }, { "binary_name": "vim-lesstif", "binary_version": "2:7.4.052-1ubuntu3.1+esm4" }, { "binary_name": "vim-nox", "binary_version": "2:7.4.052-1ubuntu3.1+esm4" }, { "binary_name": "vim-nox-dbgsym", "binary_version": "2:7.4.052-1ubuntu3.1+esm4" }, { "binary_name": "vim-runtime", "binary_version": "2:7.4.052-1ubuntu3.1+esm4" }, { "binary_name": "vim-tiny", "binary_version": "2:7.4.052-1ubuntu3.1+esm4" }, { "binary_name": "vim-tiny-dbgsym", "binary_version": "2:7.4.052-1ubuntu3.1+esm4" } ], "ubuntu_priority": "low", "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro" }
{ "binaries": [ { "binary_name": "vim", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-athena", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-athena-dbgsym", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-athena-py2", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-athena-py2-dbgsym", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-common", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-common-dbgsym", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-dbgsym", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-doc", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-gnome", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-gnome-dbgsym", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-gnome-py2", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-gnome-py2-dbgsym", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-gtk", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-gtk-dbgsym", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-gtk-py2", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-gtk-py2-dbgsym", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-gtk3", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-gtk3-dbgsym", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-gtk3-py2", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-gtk3-py2-dbgsym", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-gui-common", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-nox", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-nox-dbgsym", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-nox-py2", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-nox-py2-dbgsym", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-runtime", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-tiny", "binary_version": "2:7.4.1689-3ubuntu1.5" }, { "binary_name": "vim-tiny-dbgsym", "binary_version": "2:7.4.1689-3ubuntu1.5" } ], "ubuntu_priority": "low", "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "vim", "binary_version": "2:8.0.1453-1ubuntu1" }, { "binary_name": "vim-athena", "binary_version": "2:8.0.1453-1ubuntu1" }, { "binary_name": "vim-athena-dbgsym", "binary_version": "2:8.0.1453-1ubuntu1" }, { "binary_name": "vim-common", "binary_version": "2:8.0.1453-1ubuntu1" }, { "binary_name": "vim-dbgsym", "binary_version": "2:8.0.1453-1ubuntu1" }, { "binary_name": "vim-doc", "binary_version": "2:8.0.1453-1ubuntu1" }, { "binary_name": "vim-gnome", "binary_version": "2:8.0.1453-1ubuntu1" }, { "binary_name": "vim-gtk", "binary_version": "2:8.0.1453-1ubuntu1" }, { "binary_name": "vim-gtk-dbgsym", "binary_version": "2:8.0.1453-1ubuntu1" }, { "binary_name": "vim-gtk3", "binary_version": "2:8.0.1453-1ubuntu1" }, { "binary_name": "vim-gtk3-dbgsym", "binary_version": "2:8.0.1453-1ubuntu1" }, { "binary_name": "vim-gui-common", "binary_version": "2:8.0.1453-1ubuntu1" }, { "binary_name": "vim-nox", "binary_version": "2:8.0.1453-1ubuntu1" }, { "binary_name": "vim-nox-dbgsym", "binary_version": "2:8.0.1453-1ubuntu1" }, { "binary_name": "vim-runtime", "binary_version": "2:8.0.1453-1ubuntu1" }, { "binary_name": "vim-tiny", "binary_version": "2:8.0.1453-1ubuntu1" }, { "binary_name": "vim-tiny-dbgsym", "binary_version": "2:8.0.1453-1ubuntu1" }, { "binary_name": "xxd", "binary_version": "2:8.0.1453-1ubuntu1" }, { "binary_name": "xxd-dbgsym", "binary_version": "2:8.0.1453-1ubuntu1" } ], "ubuntu_priority": "low", "availability": "No subscription required" }