Back

HIGH

Heap-based Buffer Overflow in vim/vim

Published Dec 19, 2021

Description

vim is vulnerable to Heap-based Buffer Overflow

Affected products

Remediation

Red Hat statement

Red Hat Product Security has rated this issue as having a Low security impact, because the "victim" has to run an untrusted file IN SCRIPT MODE. Someone who is running untrusted files in script mode is equivalent to someone just taking a random python script and running it. Since Red Hat Enterprise Linux 6, 7 are Out-of-Support-Scope for Low/Moderate flaws, the issue is not currently planned to be addressed in future updates for RHEL-6,7. Only Important and Critical severity flaws will be addressed at this time. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/ and Red Hat Enterprise Linux Life Cycle & Updates Policy: https://access.redhat.com/support/policy/updates/errata/. Here PR:L because we need minimum user privilege to run vim application/service. and A:L because impacted components are partially available, no total loss after exploitation.

Metrics

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published Dec 19, 2021
Updated Aug 3, 2024
Reserved Dec 18, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Dec 19, 2021