CVE-2008-4677 - CVE House
Back to Database
Status published Medium CVE-2008-4677

autoload/netrw.vim (aka the Netrw Plugin) 109, 131, and other versions...

Vulnerability Description

autoload/netrw.vim (aka the Netrw Plugin) 109, 131, and other versions before 133k for Vim 7.1.266, other 7.1 versions, and 7.2 stores credentials for an FTP session, and sends those credentials when attempting to establish subsequent FTP sessions to servers on different hosts, which allows remote FTP servers to obtain sensitive information in opportunistic circumstances by logging usernames and passwords. NOTE: the upstream vendor disputes a vector involving different ports on the same host, stating "I'm assuming that they're using the same id and password on that unchanged hostname, deliberately."

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-4677

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

netrw
Vulnerable Versions:
109, 110, 111, 112, 113, 114, 115, 116, 118, 120, 121, 122, 123, 128, 131

Timeline

Official Publish: October 22nd, 2008
Last Modified: August 7th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.