Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
https://huntr.dev/bounties/e1ce0995-4df4-4dec-9cd7-3136ac3e8e71 | patch third party advisory exploit |
https://github.com/vim/vim/commit/816fbcc262687b81fc46f82f7bbeb1453addfe0c | patch |
https://support.apple.com/kb/HT213984 | third party advisory release notes |
http://seclists.org/fulldisclosure/2023/Oct/24 | third party advisory mailing list |