PT-2021-7388 · Vim+6 · Vim+6

Brammool

·

Published

2021-11-13

·

Updated

2024-08-21

·

CVE-2021-3973

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions vim (affected versions not specified)
Description The issue is related to a Heap-based Buffer Overflow in the vim text editor. It is associated with incorrect handling of CTRL-W f when no file name is present. Exploitation of this issue allows a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Heap Based Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1087
ALT-PU-2022-1711
ALT-PU-2022-1731
ALT-PU-2022-1771
AZL-6946
BDU:2022-05922
CVE-2021-3973
DLA-2947-1
MGASA-2021-0535
OESA-2021-1450
OPENSUSE-SU-2022_2102-1
SUSE-SU-2022:2102-1
SUSE-SU-2022:4619-1
USN-5247-1
USN-5433-1
USN-6965-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Suse
Ubuntu
Vim