CNCVE编号:CNCVE-20010409 CVE编号:CVE-2001-0409 安全级别:中 漏洞中文描述: 当攻击对象正在编辑完全可写目录下的文件时,vim (也就是 gvim)允许本地用户通过对backup和swap文件的symlink攻击来修改那些正在被其他用户编辑的文件。 漏洞英文描述: vim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swap files, when the victim is editing the file in a world writeable directory. 漏洞参考: SUSE:SuSE-SA:2001:12 URL:http://www.suse.de/de/support/security/2001_012_vim.txt CALDERA:CSSA-2001-014.0 URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-014.0.txt 系统类型:其他 漏洞类型:环境错误