[NetSIG] vim zero-day (fixed) ... but not emacs
Mark G.
netsig at palaceofretention.ca
Sun Apr 26 12:14:22 PDT 2026
Nice that it is patched. I just noticed, however, that FreeBSD
ships plain old vi, not vim. Is vi a default in Linux, or is
it vim instead? Curious, are there essential features that
vim has that makes it more useful than vi?
On 4/24/26 07:49, Greg H wrote:
> Here's the vim zero-day discussed last night:
>
> https://www.csoonline.com/article/4153288/vim-and-gnu-emacs-claude-code-helpfully-found-zero-day-exploits-for-both.html
> <https://www.csoonline.com/article/4153288/vim-and-gnu-emacs-claude-code-helpfully-found-zero-day-exploits-for-both.html>
>
> /“An attacker who can deliver a crafted file to a victim achieves arbitrary command execution with the privileges of the
> user running Vim,” Vim maintainers noted in their security advisory <https://github.com/vim/vim/security/advisories/
> GHSA-2gmj-rpqf-pxvh>. “The attack requires only that the victim opens the file; no further interaction is needed.”/
>
> I forgot to mention an emacs flaw was also discovered.
>
> Greg
>
>
More information about the NetSIG
mailing list