QID 353117

Date Published: 2022-01-24

QID 353117: Amazon Linux Security Advisory for vim : ALAS-2022-1557

vim is vulnerable to heap-based buffer overflow (cve-2021-3903) a flaw was found in vim.
A possible heap-based buffer overflow could allow an attacker to input a specially crafted file leading to a crash or code execution.
The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. (
( CVE-2021-3927) a flaw was found in vim.
A possible stack-based buffer overflow could allow an attacker to input a specially crafted file leading to a crash or code execution.
( CVE-2021-3928) a flaw was found in vim.
A possible heap use-after-free vulnerability could allow an attacker to input a specially crafted file leading to a crash or code execution.
The highest threat from this vulnerability is to system availability.

Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 8 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    Please refer to Amazon advisory: ALAS-2022-1557 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ALAS-2022-1557 Amazon Linux URL Logo alas.aws.amazon.com/ALAS-2022-1557.html