← Back

Syntastic Project

syntastic_project

1 CVE • 1 product

Products (1)

Click to collapse
Toggle
Syntastic
syntastic

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Syntastic Project
2Debian Linux
Syntastic
Nov 21, 2024
May 20, 2018
N/A· v4
7.5 HIGH· v3
8.5 HIGH· v2
Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potentially the root). This improper handling might be exploited for arbitrar...Show more
Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potentially the root). This improper handling might be exploited for arbitrary code execution via a malicious gcc plugin, if an attacker has write access to a directory that is a parent of the base directory of the project being checked. NOTE: exploitation is more difficult after 3.8.0 because filename prediction may be needed.Show less