High severity8.6NVD Advisory· Published Jun 5, 2019· Updated Jun 17, 2026
CVE-2019-12735
CVE-2019-12735
Description
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
31- Vim/Vimdescription
- osv-coords28 versionspkg:rpm/opensuse/neovim&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/neovim&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/neovim&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/vim&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/vim&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/vim&distro=openSUSE%20Tumbleweedpkg:rpm/suse/neovim&distro=SUSE%20Package%20Hub%2015pkg:rpm/suse/neovim&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/vim&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP1pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/vim&distro=SUSE%20OpenStack%20Cloud%207
< 0.3.1-bp150.2.6.1+ 27 more
- (no CPE)range: < 0.3.1-bp150.2.6.1
- (no CPE)range: < 0.3.1-bp150.2.6.1
- (no CPE)range: < 0.5.1-1.1
- (no CPE)range: < 8.0.1568-lp151.5.3.1
- (no CPE)range: < 8.0.1568-lp151.5.3.1
- (no CPE)range: < 8.2.3408-1.2
- (no CPE)range: < 0.3.1-bp150.2.6.1
- (no CPE)range: < 0.3.7-bp151.3.3.1
- (no CPE)range: < 7.4.326-17.3.1
- (no CPE)range: < 7.4.326-17.3.1
- (no CPE)range: < 7.4.326-17.3.1
- (no CPE)range: < 8.0.1568-5.3.1
- (no CPE)range: < 8.0.1568-5.3.1
- (no CPE)range: < 8.0.1568-5.3.1
- (no CPE)range: < 8.0.1568-5.3.1
- (no CPE)range: < 7.2-8.21.3.1
- (no CPE)range: < 7.2-8.21.3.1
- (no CPE)range: < 7.4.326-17.3.1
- (no CPE)range: < 7.4.326-17.3.1
- (no CPE)range: < 7.4.326-17.3.1
- (no CPE)range: < 7.4.326-17.3.1
- (no CPE)range: < 7.4.326-17.3.1
- (no CPE)range: < 7.4.326-17.3.1
- (no CPE)range: < 7.4.326-17.3.1
- (no CPE)range: < 7.4.326-17.3.1
- (no CPE)range: < 7.4.326-17.3.1
- (no CPE)range: < 7.4.326-17.3.1
- (no CPE)range: < 7.4.326-17.3.1
Patches
Vulnerability mechanics
References
32- github.com/neovim/neovim/pull/10082nvdPatchThird Party Advisory
- github.com/vim/vim/commit/53575521406739cf20bbe4e384d88e7dca11f040nvdPatchThird Party Advisory
- github.com/numirias/security/blob/master/doc/2019-06-04_ace-vim-neovim.mdnvdExploitPatchThird Party Advisory
- bugs.debian.org/930020nvdMailing ListThird Party Advisory
- bugs.debian.org/930024nvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-06/msg00031.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2019-06/msg00036.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2019-06/msg00037.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2019-07/msg00034.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2019-07/msg00050.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2019-08/msg00075.htmlnvd
- www.securityfocus.com/bid/108724nvd
- access.redhat.com/errata/RHSA-2019:1619nvd
- access.redhat.com/errata/RHSA-2019:1774nvd
- access.redhat.com/errata/RHSA-2019:1793nvd
- access.redhat.com/errata/RHSA-2019:1947nvd
- lists.debian.org/debian-lts-announce/2019/08/msg00003.htmlnvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2BMDSHTF754TITC6AQJPCS5IRIDMMIM7/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TRIRBC2YRGKPAWVRMZS4SZTGGCVRVZPR/nvd
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2BMDSHTF754TITC6AQJPCS5IRIDMMIM7/nvd
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TRIRBC2YRGKPAWVRMZS4SZTGGCVRVZPR/nvd
- seclists.org/bugtraq/2019/Jul/39nvd
- seclists.org/bugtraq/2019/Jun/33nvd
- security.gentoo.org/glsa/202003-04nvd
- support.f5.com/csp/article/K93144355nvd
- support.f5.com/csp/article/K93144355nvd
- support.f5.com/csp/article/K93144355nvd
- usn.ubuntu.com/4016-1/nvd
- usn.ubuntu.com/4016-2/nvd
- www.debian.org/security/2019/dsa-4467nvd
- www.debian.org/security/2019/dsa-4487nvd
- www.exploit-db.com/exploits/46973nvd
News mentions
0No linked articles in our index yet.