Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3903

Опубликовано: 24 окт. 2021
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

vim is vulnerable to Heap-based Buffer Overflow

Отчет

This flaw is marked as Low Impact because it requires a user to run an untrusted/malicious Vim script using the -s option at the command line. Untrusted Vim scripts should never be run as they can already execute arbitrary shell commands. The security issue raised by this flaw would be no worse than what is already possible when running untrusted Vim scripts. Vim as shipped in Red Hat Enterprise Linux 8 is not affected by this flaw. The flaw is out of support scope for Red Hat Enterprise Linux 6 and 7.

Меры по смягчению последствий

Do not run untrusted vim scripts with -s {scriptin} as it is never safe to do so.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/openshift-hive-rhel8Not affected
Red Hat Enterprise Linux 6vimOut of support scope
Red Hat Enterprise Linux 7vimOut of support scope
Red Hat Enterprise Linux 8vimNot affected
Red Hat Enterprise Linux 9vimFixedRHSA-2024:940512.11.2024
Red Hat Enterprise Linux 9vimFixedRHSA-2024:940512.11.2024

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2018558vim: heap-based buffer overflow vulnerability

EPSS

Процентиль: 55%
0.00323
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 4 года назад

vim is vulnerable to Heap-based Buffer Overflow

CVSS3: 7.8
nvd
почти 4 года назад

vim is vulnerable to Heap-based Buffer Overflow

CVSS3: 7.8
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 7.8
debian
почти 4 года назад

vim is vulnerable to Heap-based Buffer Overflow

CVSS3: 7.8
github
около 3 лет назад

vim is vulnerable to Heap-based Buffer Overflow

EPSS

Процентиль: 55%
0.00323
Низкий

5.5 Medium

CVSS3