Bug#894736: Checker config files allow arbitrary code execution scenarios

2018-05-20 Thread Salvatore Bonaccorso
Control: retitle -1 vim-syntastic: CVE-2018-11319: Checker config files allow arbitrary code execution scenarios Hi This issue was assigned CVE-2018-11319. Regards, Salvatore

Bug#894736: Checker config files allow arbitrary code execution scenarios

2018-04-19 Thread Andrea Capriotti
Il giorno mar, 03/04/2018 alle 20.03 +0200, Enrico Zini ha scritto: > Package: vim-syntastic > Version: 3.8.0-1 > Severity: serious > > Hello, > > syntastic has a Configuration Files[1] feature enabled for several > checkers, where: > > a configuration file is looked up in the directory of

Bug#894736: Checker config files allow arbitrary code execution scenarios

2018-04-03 Thread Enrico Zini
Package: vim-syntastic Version: 3.8.0-1 Severity: serious Hello, syntastic has a Configuration Files[1] feature enabled for several checkers, where: a configuration file is looked up in the directory of the file being checked, then upwards in parent directories. The search stops either