On 7/28/06, Marc Weber <[EMAIL PROTECTED]> wrote:

In case it's a still a vim issue or we don't wont it it would be easy to
add a "accept_remote_orders_from_different_user and let vim send not
only the command but also the username so the server might check..
I'll try to investigate some more time to get to know wether it's as
easy as this to find a running shell and send some keys to it.

Wait...can other users send commands to my Vim?  Yes, as it turns out,
they can.  That is definitely a /big/ security issue.

Bram, this has to be amended immediately.  If other users should be
able to connect to a remote Vim, then at least there should be some
kind of user/password scheme that the user starting the server can set
up.  Allowing anyone to connect to another Vim is definitely not good.

 nikolai

Reply via email to