PT-2021-4898 · Vim+9 · Vim+9

Brammool

·

Published

2021-09-07

·

Updated

2023-01-11

·

CVE-2021-3778

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vim (affected versions not specified)
Description The issue is related to a Heap-based Buffer Overflow in the vim text editor, specifically in the utf ptr2char() function. This overflow occurs when the write operation exceeds the buffer boundaries in memory. Exploitation of this issue could allow an attacker to execute arbitrary code or cause a denial of service using a specially crafted file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2021:4517
ALT-PU-2022-1087
ALT-PU-2022-1711
ALT-PU-2022-1731
ALT-PU-2022-1771
BDU:2021-05633
CESA-2021_4517
CVE-2021-3778
DLA-2876-1
MGASA-2021-0481
OESA-2021-1356
OPENSUSE-SU-2022:0736-1
OPENSUSE-SU-2022_0736-1
OPENSUSE-SU-2022_2102-1
RHSA-2021:4517
RHSA-2021_4517
RLSA-2021:4517
SUSE-SU-2022:0736-1
SUSE-SU-2022:0736-2
SUSE-SU-2022:2102-1
SUSE-SU-2022:4619-1
SUSE-SU-2022_0736-1
USN-5093-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Vim