First published: Fri Oct 15 2021(Updated: )
vim is vulnerable to Heap-based Buffer Overflow
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Vim | <8.2.3489 | |
Fedora | =33 | |
Fedora | =35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3875 is classified as a high-severity vulnerability due to the potential for exploitation leading to arbitrary code execution.
To fix CVE-2021-3875, update Vim to version 8.2.3489 or later, or apply vendor-specific patches where available.
CVE-2021-3875 affects various versions of Vim, including versions prior to 8.2.3489 and Fedora 33 and 35 distributions.
CVE-2021-3875 can be exploited through a heap-based buffer overflow, allowing an attacker to execute arbitrary code.
Currently, disabling certain functionalities in Vim or using alternative text editors may serve as temporary workarounds for CVE-2021-3875.