CVE-2017-11109: Use After Free
Last updated 25 August 2025
Other sources
Vim 8.0 allows attackers to cause a denial of service (invalid free) or possibly have unspecified other impact via a crafted source (aka -S) file. NOTE: there might be a limited number of scenarios in which this has security relevance.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/vimto a version that resolves this vulnerability.Fixed in 2:8.2.2434-3+deb11u1Fixed in 2:8.2.2434-3+deb11u3Fixed in 2:9.0.1378-2+deb12u2Fixed in 2:9.1.1230-2Fixed in 2:9.2.0524-1Fixed in 2:9.2.0782-1 - Compensating control
Mitigate the risk by avoiding processing untrusted files as Vim scripts using the -S option (do not allow attackers to provide the crafted -S file).
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11109?
CVE-2017-11109 has a severity rating that could lead to denial of service if exploited.
How do I fix CVE-2017-11109?
To mitigate CVE-2017-11109, upgrade to a version of Vim that is not affected, specifically versions later than 8.0.
What systems are affected by CVE-2017-11109?
CVE-2017-11109 affects Vim version 8.0 and certain Debian packages including specific versions of Vim.
What type of vulnerability is CVE-2017-11109?
CVE-2017-11109 is classified as a denial of service vulnerability.
Can CVE-2017-11109 lead to other impacts aside from denial of service?
While primarily a denial of service vulnerability, CVE-2017-11109 may potentially have unspecified other impacts.