PT-2021-7390 · Vim+6 · Vim+6

Brammool

·

Published

2021-10-25

·

Updated

2024-08-21

·

CVE-2021-3974

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions vim (affected versions not specified)
Description The issue is related to a Use After Free vulnerability in the vim text editor, specifically in the regexp nfa.c component. This vulnerability allows a remote attacker to access confidential data, compromise its integrity, and cause a denial of service by exploiting the use of memory after it has been freed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1087
ALT-PU-2022-1711
ALT-PU-2022-1731
ALT-PU-2022-1771
AZL-6947
BDU:2022-05924
CVE-2021-3974
DLA-2947-1
DLA-3182-1
MGASA-2021-0535
OESA-2021-1450
OPENSUSE-SU-2022_2102-1
SUSE-SU-2022:2102-1
SUSE-SU-2022:4619-1
USN-5247-1
USN-5433-1
USN-6965-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Suse
Ubuntu
Vim