HIGH
libvterm: NULL pointer dereference in vterm_screen_set_callbacks
Published Feb 24, 2019
7.5
HIGHCVSS 3.0
EPSS 2.89%
Description
libvterm through 0+bzr726, as used in Vim and other products, mishandles certain out-of-memory conditions, leading to a denial of service (application crash), related to screen.c, state.c, and vterm.c.
Affected products
Remediation
Red Hat statement
Red Hat has determined this flaw to be of LOW impact as the vulnerable code is not used when compiling and building /`usr/bin/vi`; the code is not used because `/usr/bin/vi` is built with `--with-features=small`.
Weaknesses (1)
References (8)
- https://access.redhat.com/security/cve/CVE-2018-20786 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1680588 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-13329 Advisory
- https://github.com/vim/vim/commit/cd929f7ba8cc5b6d6dcf35c8b34124e969fed6b8 x_refsource_MISCPatchThird Party Advisory
- https://github.com/vim/vim/issues/3711 x_refsource_MISCExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-20786
- https://usn.ubuntu.com/4309-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2018-20786
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-20786 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1680588 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-13329 | Advisory | |
| https://github.com/vim/vim/commit/cd929f7ba8cc5b6d6dcf35c8b34124e969fed6b8 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/vim/vim/issues/3711 | x_refsource_MISCExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-20786 | ||
| https://usn.ubuntu.com/4309-1/ | vendor-advisoryx_refsource_UBUNTU | |
| https://www.cve.org/CVERecord?id=CVE-2018-20786 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 24, 2019
Updated Aug 5, 2024
Reserved Feb 24, 2019
Link CVE-2018-20786
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2018-13329 Assigner mitre
Published Feb 24, 2019
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2018-13329