Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-34714

Опубликовано: 30 мар. 2026
Источник: debian

Описание

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
vimfixed2:9.2.0315-1package
vimnot-affectedtrixiepackage
vimnot-affectedbookwormpackage
vimnot-affectedbullseyepackage

Примечания

  • https://github.com/vim/vim/security/advisories/GHSA-2gmj-rpqf-pxvh

  • Introduced with: https://github.com/vim/vim/commit/be5bd4d6292fddcc103091407792730aaa48cc48 (v9.1.1391)

  • Fixed by: https://github.com/vim/vim/commit/664701eb7576edb7c7c7d9f2d600815ec1f43459 (v9.2.0272)

Связанные уязвимости

CVSS3: 9.2
ubuntu
4 месяца назад

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

CVSS3: 8.6
redhat
4 месяца назад

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

CVSS3: 9.2
nvd
4 месяца назад

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

CVSS3: 8.5
msrc
4 месяца назад

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

CVSS3: 9.2
github
4 месяца назад

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.