QID 198647

Date Published: 2022-02-01

QID 198647: Ubuntu Security Notification for Vim Vulnerabilities (USN-5247-1)

Vim incorrectly handled parsing of filenames in itssearch functionality.
Vim incorrectly handled memory when opening andsearching the contents of certain files.
Vim incorrectly handled memory when opening and editingcertain files.
Vim incorrectly handled memory when opening and editingcertain files.
Vim incorrectly handled memory when opening and editingcertain files.

If a user was tricked into opening a specially craftedfile, an attacker could crash the application, leading to a denial ofservice.
If a user was tricked into openinga specially crafted file, an attacker could crash the application, leading toa denial of service, or possibly achieve code execution with user privileges.
If a user was tricked into opening a specially crafted file, anattacker could crash the application, leading to a denial of service, orpossibly achieve code execution with user privileges.
If a user was tricked into opening a specially crafted file, anattacker could crash the application, leading to a denial of service, orpossibly achieve code execution with user privileges.
If a user was tricked into opening a specially crafted file, anattacker could crash the application, leading to a denial of service, orpossibly achieve code execution with user privileges.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5247-1 for updates and patch information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    USN-5247-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5247-1