CVE-2021-3973: Heap-based Buffer Overflow in vim/vim
Published Nov 19, 2021
·Updated
Last updated 21 August 2024
Other sources
vim is vulnerable to Heap-based Buffer Overflow
— Launchpad
Affected Software
5 affected componentsFixes available
vim Vim<8.2.3611
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Debian Debian Linux=9.0
debian/vim<=2:8.2.2434-3+deb11u1, <=2:8.2.2434-3+deb11u3
2:9.0.1378-2+deb12u22:9.1.1230-1
Remediation
Event History
Nov 19, 2021
CVE Published
via MITRE·11:35 AM
Data Sourced
via MITRE·11:35 AM
DescriptionSeverityWeakness
Jan 12, 2024
Data Sourced
via Launchpad·12:00 AM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:34 AM
RemedyDescriptionSeverityAffected Software
Mar 27, 2025
Data Sourced
via Debian·04:24 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2021-3973?
CVE-2021-3973 is a vulnerability in vim that allows for a heap-based buffer overflow.
2
How does CVE-2021-3973 affect vim?
CVE-2021-3973 affects vim by allowing an attacker to overflow the heap-based buffer, potentially leading to arbitrary code execution.
3
What is the severity of CVE-2021-3973?
The severity of CVE-2021-3973 is high.
4
Which versions of vim are affected by CVE-2021-3973?
Versions of vim up to 8.2.3611 are affected by CVE-2021-3973.
5
How can I fix CVE-2021-3973?
To fix CVE-2021-3973, update vim to version 8.2.3611 or later.