Bug#930024: neovim: Arbitrary Code Execution exploit on all neovim versions < 0.3.6 via modelines

2019-06-12 Thread Salvatore Bonaccorso
Control: severity -1 serious On Fri, Jun 07, 2019 at 07:51:19AM +0200, Salvatore Bonaccorso wrote: > Hi James, > > On Thu, Jun 06, 2019 at 09:29:14PM -0400, James McCoy wrote: > > Control: found -1 0.3.4-2 > > > > On Wed, Jun 05, 2019 at 03:33:23PM +0200, Salvatore Bonaccorso wrote: > > >

Bug#930024: neovim: Arbitrary Code Execution exploit on all neovim versions < 0.3.6 via modelines

2019-06-06 Thread Salvatore Bonaccorso
Hi James, On Thu, Jun 06, 2019 at 09:29:14PM -0400, James McCoy wrote: > Control: found -1 0.3.4-2 > > On Wed, Jun 05, 2019 at 03:33:23PM +0200, Salvatore Bonaccorso wrote: > > Control: retitle neovim: CVE-2019-12735: Modelines allow arbitrary code > > execution > > > > On Wed, Jun 05, 2019 at

Bug#930024: neovim: Arbitrary Code Execution exploit on all neovim versions < 0.3.6 via modelines

2019-06-06 Thread James McCoy
Control: found -1 0.3.4-2 On Wed, Jun 05, 2019 at 03:33:23PM +0200, Salvatore Bonaccorso wrote: > Control: retitle neovim: CVE-2019-12735: Modelines allow arbitrary code > execution > > On Wed, Jun 05, 2019 at 03:14:43AM -0700, Matthew Crews wrote: > > Source: neovim > > Severity: important > >

Bug#930024: neovim: Arbitrary Code Execution exploit on all neovim versions < 0.3.6 via modelines

2019-06-05 Thread Salvatore Bonaccorso
Control: retitle neovim: CVE-2019-12735: Modelines allow arbitrary code execution On Wed, Jun 05, 2019 at 03:14:43AM -0700, Matthew Crews wrote: > Source: neovim > Severity: important > Tags: upstream > > Dear Maintainer, > > Neovim versions < 0.3.6 are subject to an Arbitrary Code Execution

Bug#930024: neovim: Arbitrary Code Execution exploit on all neovim versions < 0.3.6 via modelines

2019-06-05 Thread Matthew Crews
Source: neovim Severity: important Tags: upstream Dear Maintainer, Neovim versions < 0.3.6 are subject to an Arbitrary Code Execution exploit via modelines, as described in this blogpost: https://github.com/numirias/security/blob/master/doc/2019-06-04_ace-vim- neovim.md Upgrading the Neovim