Buffer Overflow Affecting vim/vim Open this link in a new tab package, versions [,8.2.4969)


0.0
medium
  • Exploit Maturity

    Proof of concept

  • Attack Complexity

    Low

  • Availability

    High

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • snyk-id

    SNYK-UNMANAGED-VIMVIM-2840621

  • published

    20 May 2022

  • disclosed

    17 May 2022

  • credit

    TDHX ICS Security

How to fix?

Upgrade vim/vim to version 8.2.4969 or higher.

Overview

Affected versions of this package are vulnerable to Buffer Overflow by changing the text in the visual mode which may cause invalid memory access.

PoC

./vim -u NONE -i NONE -n -m -X -Z -e -s -S /mnt/share/max/fuzz/poc/vim/poc_h8_s.dat -c :qa!