Описание
vim is vulnerable to Heap-based Buffer Overflow
There's an out-of-bounds read flaw in Vim's ex_docmd.c. An attacker who is capable of tricking a user into opening a specially crafted file could trigger an out-of-bounds read on a memmove operation, potentially causing an impact to application availability.
Отчет
This flaw does not affect vim as shipped in any versions of Red Hat Enterprise Linux because it was introduced in a newer version than those shipped.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/openshift-hive-rhel8 | Not affected | ||
| Red Hat Enterprise Linux 6 | vim | Not affected | ||
| Red Hat Enterprise Linux 7 | vim | Not affected | ||
| Red Hat Enterprise Linux 8 | vim | Not affected | ||
| Red Hat Enterprise Linux 9 | vim | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2014661vim: heap-based buffer overflow
EPSS
Процентиль: 33%
0.0013
Низкий
5.5 Medium
CVSS3
EPSS
Процентиль: 33%
0.0013
Низкий
5.5 Medium
CVSS3