First published: Wed Sep 15 2021(Updated: )
vim is vulnerable to Heap-based Buffer Overflow
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Vim Vim | <8.2.3409 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
Debian Debian Linux | =9.0 | |
NetApp ONTAP Select Deploy administration utility |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3778 is a vulnerability found in vim that allows for a heap-based buffer overflow.
CVE-2021-3778 has a severity rating of high (7.8).
Versions up to and excluding Vim 8.2.3409, Fedora 33, Fedora 34, Fedora 35, Debian Linux 9.0, and NetApp ONTAP Select Deploy administration utility are affected by CVE-2021-3778.
To fix CVE-2021-3778, update your vim installation to a version that includes the fix, or follow the recommendations provided by the vendor or software developer.
You can find more information about CVE-2021-3778 on the following references: [reference 1](http://www.openwall.com/lists/oss-security/2021/10/01/1), [reference 2](https://github.com/vim/vim/commit/65b605665997fad54ef39a93199e305af2fe4d7f), [reference 3](https://huntr.dev/bounties/d9c17308-2c99-4f9f-a706-f7f72c24c273).