First published: Tue Oct 19 2021(Updated: )
Last updated 24 July 2024
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Vim Vim | <8.2.3487 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =35 | |
Debian Debian Linux | =9.0 | |
debian/vim | <=2:8.2.2434-3+deb11u1 | 2:9.0.1378-2 2:9.1.0709-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3872 is a vulnerability in vim that allows for a heap-based buffer overflow.
CVE-2021-3872 has a severity rating of 7.8, which is considered high.
Vim versions 8.2.2434-3ubuntu3.1, 8.1.2269-1ubuntu5.4, 8.2.2434-1ubuntu1.2, 8.2.3487, 8.2.3565-1ubuntu2, 8.1.0875-5+deb10u6, 8.2.3565-1ubuntu2, 9.0.1378-2, 9.0.1894-1, and 9.0.2018-1 are affected.
To fix CVE-2021-3872, you should update your vim package to version 8.2.3487 or later.
You can find more information about CVE-2021-3872 at the following links: [Mitre](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3872), [Github](https://github.com/vim/vim/commit/826bfe4bbd7594188e3d74d2539d9707b1c6a14b), [Huntr](https://huntr.dev/bounties/c958013b-1c09-4939-92ca-92f50aa169e8).