[NetSIG] vim zero-day (fixed) ... but not emacs
Craig Miller
cvmiller at gmail.com
Sun Apr 26 16:48:49 PDT 2026
Mark,
On MX Linux vi is (round-about) connect to vim.tiny, which vim is also
linked to. So there is no difference between vi and vim.
/usr/bin$ ls -l vi*
lrwxrwxrwx 1 root root 20 May 4 2023 vi -> /etc/alternatives/vi
lrwxrwxrwx 1 root root 22 Feb 14 2023 view -> /etc/alternatives/view
-rwxr-xr-x 1 root root 32288 Feb 28 2020 viewres
lrwxrwxrwx 1 root root 8 Sep 14 2024 vim -> vim.tiny
-rwxr-xr-x 1 root root 1082 Jul 14 2024 vimdot
-rwxr-xr-x 1 root root 1629584 Feb 15 2025 vim.tiny
-rwxr-xr-x 1 root root 239 Dec 8 2022 virtualenv
cvmiller at ohe /usr/bin$
cvmiller at ohe /usr/bin$
cvmiller at ohe /usr/bin$ ls -l /etc/alternatives/vi
lrwxrwxrwx 1 root root 17 May 4 2023 /etc/alternatives/vi -> /usr/bin/vim.tiny
On Alpine Linux, vi is part of busybox (a multicall binary), and there
is no vim by default.
On PiOS (bookworm), there is vi, and no vim (be default).
So I guess the answer is: "it depends"
Craig....
On 4/26/26 12:14, Mark G. wrote:
> Nice that it is patched. I just noticed, however, that FreeBSD
> ships plain old vi, not vim. Is vi a default in Linux, or is
> it vim instead? Curious, are there essential features that
> vim has that makes it more useful than vi?
>
>
>
>
> On 4/24/26 07:49, Greg H wrote:
>> Here's the vim zero-day discussed last night:
>>
>> https://www.csoonline.com/article/4153288/vim-and-gnu-emacs-claude-code-helpfully-found-zero-day-exploits-for-both.html
>> <https://www.csoonline.com/article/4153288/vim-and-gnu-emacs-claude-code-helpfully-found-zero-day-exploits-for-both.html>
>>
>>
>> /“An attacker who can deliver a crafted file to a victim achieves
>> arbitrary command execution with the privileges of the user running
>> Vim,” Vim maintainers noted in their security advisory
>> <https://github.com/vim/vim/security/advisories/
>> GHSA-2gmj-rpqf-pxvh>. “The attack requires only that the victim opens
>> the file; no further interaction is needed.”/
>>
>> I forgot to mention an emacs flaw was also discovered.
>>
>> Greg
>>
>>
>
--
IPv6 is the future, the future is here
http://ipv6hawaii.org/
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://vicpimakers.ca/pipermail/netsig_vicpimakers.ca/attachments/20260426/bde40048/attachment.htm>
More information about the NetSIG
mailing list