{"id":"ECHO-aef3-a0e0-f4dc","summary":"Disputed by upstream.\nVim ignores umask when creating a swap file resulting in\nfiles that may be world readable or otherwise accessible in\nways not intended by the user running the vi binary. Vim\ncreates the .swp file according to the permissions of the\nfile being edited, deliberately ignoring the umask.\nhttps://security-tracker.debian.org/tracker/CVE-2017-1000382\n","modified":"2026-09-15T03:33:35.928242028Z","published":"2025-09-15T01:08:45.432839Z","withdrawn":"2026-04-12T13:58:47.682Z","upstream":["CVE-2017-1000382"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2017-1000382"}],"affected":[{"package":{"name":"vim","ecosystem":"Echo","purl":"pkg:deb/echo/vim"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:9.2.0218-1+e1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-aef3-a0e0-f4dc.json"}}],"schema_version":"1.9.0"}