Описание
vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer overflow.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | vim | Will not fix | ||
| Red Hat Enterprise Linux 6 | vim | Will not fix | ||
| Red Hat Enterprise Linux 7 | vim | Will not fix |
Показывать по
10
Дополнительная информация
Статус:
Low
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1421613vim: Tree length values not validated properly when handling a spell file
2.5 Low
CVSS3
Связанные уязвимости
CVSS3: 9.8
ubuntu
почти 9 лет назад
vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer overflow.
CVSS3: 9.8
nvd
почти 9 лет назад
vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer overflow.
CVSS3: 9.8
debian
почти 9 лет назад
vim before patch 8.0.0322 does not properly validate values for tree l ...
2.5 Low
CVSS3