UBUNTU-CVE-2017-17087

Source
https://ubuntu.com/security/CVE-2017-17087
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-17087.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2017-17087
Related
Published
2017-12-01T08:29:00Z
Modified
2017-12-01T08:29:00Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
  • 5.5 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.

References

Affected packages

Ubuntu:Pro:14.04:LTS / vim

Package

Name
vim
Purl
pkg:deb/ubuntu/vim?arch=src?distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:7.4.052-1ubuntu3.1+esm4

Affected versions

2:7.*

2:7.4.000-1ubuntu2
2:7.4.052-1ubuntu1
2:7.4.052-1ubuntu2
2:7.4.052-1ubuntu3
2:7.4.052-1ubuntu3.1
2:7.4.052-1ubuntu3.1+esm1
2:7.4.052-1ubuntu3.1+esm3

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "binary_version": "2:7.4.052-1ubuntu3.1+esm4",
            "binary_name": "vim"
        },
        {
            "binary_version": "2:7.4.052-1ubuntu3.1+esm4",
            "binary_name": "vim-athena"
        },
        {
            "binary_version": "2:7.4.052-1ubuntu3.1+esm4",
            "binary_name": "vim-athena-dbgsym"
        },
        {
            "binary_version": "2:7.4.052-1ubuntu3.1+esm4",
            "binary_name": "vim-common"
        },
        {
            "binary_version": "2:7.4.052-1ubuntu3.1+esm4",
            "binary_name": "vim-common-dbgsym"
        },
        {
            "binary_version": "2:7.4.052-1ubuntu3.1+esm4",
            "binary_name": "vim-dbg"
        },
        {
            "binary_version": "2:7.4.052-1ubuntu3.1+esm4",
            "binary_name": "vim-dbgsym"
        },
        {
            "binary_version": "2:7.4.052-1ubuntu3.1+esm4",
            "binary_name": "vim-doc"
        },
        {
            "binary_version": "2:7.4.052-1ubuntu3.1+esm4",
            "binary_name": "vim-gnome"
        },
        {
            "binary_version": "2:7.4.052-1ubuntu3.1+esm4",
            "binary_name": "vim-gnome-dbgsym"
        },
        {
            "binary_version": "2:7.4.052-1ubuntu3.1+esm4",
            "binary_name": "vim-gtk"
        },
        {
            "binary_version": "2:7.4.052-1ubuntu3.1+esm4",
            "binary_name": "vim-gtk-dbgsym"
        },
        {
            "binary_version": "2:7.4.052-1ubuntu3.1+esm4",
            "binary_name": "vim-gui-common"
        },
        {
            "binary_version": "2:7.4.052-1ubuntu3.1+esm4",
            "binary_name": "vim-lesstif"
        },
        {
            "binary_version": "2:7.4.052-1ubuntu3.1+esm4",
            "binary_name": "vim-nox"
        },
        {
            "binary_version": "2:7.4.052-1ubuntu3.1+esm4",
            "binary_name": "vim-nox-dbgsym"
        },
        {
            "binary_version": "2:7.4.052-1ubuntu3.1+esm4",
            "binary_name": "vim-runtime"
        },
        {
            "binary_version": "2:7.4.052-1ubuntu3.1+esm4",
            "binary_name": "vim-tiny"
        },
        {
            "binary_version": "2:7.4.052-1ubuntu3.1+esm4",
            "binary_name": "vim-tiny-dbgsym"
        }
    ]
}

Ubuntu:16.04:LTS / vim

Package

Name
vim
Purl
pkg:deb/ubuntu/vim?arch=src?distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:7.4.1689-3ubuntu1.5

Affected versions

2:7.*

2:7.4.712-2ubuntu4
2:7.4.826-1ubuntu1
2:7.4.826-1ubuntu2
2:7.4.826-1ubuntu3
2:7.4.963-1ubuntu1
2:7.4.963-1ubuntu4
2:7.4.963-1ubuntu5
2:7.4.1689-3ubuntu1
2:7.4.1689-3ubuntu1.1
2:7.4.1689-3ubuntu1.2
2:7.4.1689-3ubuntu1.3
2:7.4.1689-3ubuntu1.4

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-athena"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-athena-dbgsym"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-athena-py2"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-athena-py2-dbgsym"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-common"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-common-dbgsym"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-dbgsym"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-doc"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-gnome"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-gnome-dbgsym"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-gnome-py2"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-gnome-py2-dbgsym"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-gtk"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-gtk-dbgsym"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-gtk-py2"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-gtk-py2-dbgsym"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-gtk3"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-gtk3-dbgsym"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-gtk3-py2"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-gtk3-py2-dbgsym"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-gui-common"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-nox"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-nox-dbgsym"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-nox-py2"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-nox-py2-dbgsym"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-runtime"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-tiny"
        },
        {
            "binary_version": "2:7.4.1689-3ubuntu1.5",
            "binary_name": "vim-tiny-dbgsym"
        }
    ]
}

Ubuntu:18.04:LTS / vim

Package

Name
vim
Purl
pkg:deb/ubuntu/vim?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:8.0.1453-1ubuntu1

Affected versions

2:8.*

2:8.0.0197-4ubuntu5
2:8.0.1144-1ubuntu1
2:8.0.1401-1ubuntu1
2:8.0.1401-1ubuntu2
2:8.0.1401-1ubuntu3

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "binary_version": "2:8.0.1453-1ubuntu1",
            "binary_name": "vim"
        },
        {
            "binary_version": "2:8.0.1453-1ubuntu1",
            "binary_name": "vim-athena"
        },
        {
            "binary_version": "2:8.0.1453-1ubuntu1",
            "binary_name": "vim-athena-dbgsym"
        },
        {
            "binary_version": "2:8.0.1453-1ubuntu1",
            "binary_name": "vim-common"
        },
        {
            "binary_version": "2:8.0.1453-1ubuntu1",
            "binary_name": "vim-dbgsym"
        },
        {
            "binary_version": "2:8.0.1453-1ubuntu1",
            "binary_name": "vim-doc"
        },
        {
            "binary_version": "2:8.0.1453-1ubuntu1",
            "binary_name": "vim-gnome"
        },
        {
            "binary_version": "2:8.0.1453-1ubuntu1",
            "binary_name": "vim-gtk"
        },
        {
            "binary_version": "2:8.0.1453-1ubuntu1",
            "binary_name": "vim-gtk-dbgsym"
        },
        {
            "binary_version": "2:8.0.1453-1ubuntu1",
            "binary_name": "vim-gtk3"
        },
        {
            "binary_version": "2:8.0.1453-1ubuntu1",
            "binary_name": "vim-gtk3-dbgsym"
        },
        {
            "binary_version": "2:8.0.1453-1ubuntu1",
            "binary_name": "vim-gui-common"
        },
        {
            "binary_version": "2:8.0.1453-1ubuntu1",
            "binary_name": "vim-nox"
        },
        {
            "binary_version": "2:8.0.1453-1ubuntu1",
            "binary_name": "vim-nox-dbgsym"
        },
        {
            "binary_version": "2:8.0.1453-1ubuntu1",
            "binary_name": "vim-runtime"
        },
        {
            "binary_version": "2:8.0.1453-1ubuntu1",
            "binary_name": "vim-tiny"
        },
        {
            "binary_version": "2:8.0.1453-1ubuntu1",
            "binary_name": "vim-tiny-dbgsym"
        },
        {
            "binary_version": "2:8.0.1453-1ubuntu1",
            "binary_name": "xxd"
        },
        {
            "binary_version": "2:8.0.1453-1ubuntu1",
            "binary_name": "xxd-dbgsym"
        }
    ]
}