CVE-2021-3903: Heap-based Buffer Overflow in vim/vim
Last updated 24 July 2024
Other sources
vim is vulnerable to Heap-based Buffer Overflow
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-3903.
What software is affected by CVE-2021-3903?
The affected software is vim.
What is the severity rating of CVE-2021-3903?
The severity rating of CVE-2021-3903 is high (7.8).
How can I fix CVE-2021-3903?
To fix CVE-2021-3903, ensure that you are using the recommended versions of vim: '2:8.0.1453-1ubuntu1.7', '2:8.1.2269-1ubuntu5.4', '2:8.2.2434-1ubuntu1.2', '2:8.2.2434-3ubuntu3.1', '2:7.4.052-1ubuntu3.1+', '8.2.3564', '2:7.4.1689-3ubuntu1.5+', '2:8.2.3565-1ubuntu2' for Ubuntu and '2:9.0.1378-2', '2:9.0.1894-1', '2:9.0.2018-1' for Debian. Install the latest available patches and updates.
Where can I find more information about CVE-2021-3903?
You can find more information about CVE-2021-3903 on the MITRE CVE database (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3903), the Huntr.dev website (https://huntr.dev/bounties/35738a4f-55ce-446c-b836-2fb0b39625f8), and the GitHub commit (https://github.com/vim/vim/commit/777e7c21b7627be80961848ac560cb0a9978ff43).