CVE-2021-4193
Severity:
MEDIUM
Type:
CWE-125
Out-of-bounds Read
Publication date:
31/12/2021
Last modified:
09/11/2022
Description
vim is vulnerable to Out-of-bounds Read
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
Medium
Vulnerable products and versions
- cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2020-001:*:*:*:*:*:*
To consult the complete list of products and versions see this page
References to Advisories, Solutions, and Tools
- https://github.com/vim/vim/commit/94f3192b03ed27474db80b4d3a409e107140738b (Source:MISC)
- https://huntr.dev/bounties/92c1940d-8154-473f-84ce-0de43b0c2eb0 (Source:CONFIRM)
- http://www.openwall.com/lists/oss-security/2022/01/15/1 (Source:MLIST)
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3FH2J57GDA2WMBS6J56F6QQRA6BXQQFZ/ (Source:FEDORA)
- https://lists.debian.org/debian-lts-announce/2022/03/msg00018.html (Source:MLIST)
- https://support.apple.com/kb/HT213183 (Source:CONFIRM)
- http://seclists.org/fulldisclosure/2022/Mar/29 (Source:FULLDISC)
- https://support.apple.com/kb/HT213256 (Source:CONFIRM)
- http://seclists.org/fulldisclosure/2022/May/35 (Source:FULLDISC)
- https://support.apple.com/kb/HT213343 (Source:CONFIRM)
- http://seclists.org/fulldisclosure/2022/Jul/14 (Source:FULLDISC)
- https://security.gentoo.org/glsa/202208-32 (Source:GENTOO)
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html (Source:MLIST)