QID 376429

Date Published: 2022-09-07

QID 376429: Vim Heap-based buffer Overflow Vulnerability

Vim (a contraction of Vi IMproved) is a free and open-source, screen-based text editor program for Unix.

Heap-based Buffer Overflow in vim prior to 8.2.

Affected Version
Vi IMproved vim prior to 8.2

QID Detection Logic(Authenticated)
QID checks for the vulnerable versions of vim editor

Exploit will lead to Out of bounds write and Heap-based Buffer Overflow

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Refer to vim release Vim 8.2 for updates and patch information.
    Vendor References

    CVEs related to QID 376429

    Software Advisories
    Advisory ID Software Component Link