CVE-2021-3984: Heap-based Buffer Overflow in vim/vim
Published Dec 1, 2021
·Updated
Last updated 21 August 2024
Other sources
vim is vulnerable to Heap-based Buffer Overflow
Affected Software
5 affected componentsFixes available
vim Vim<8.2.3625
Fedoraproject Fedora=34
Debian Debian Linux=9.0
Debian Debian Linux=10.0
debian/vim<=2:8.2.2434-3+deb11u1, <=2:8.2.2434-3+deb11u3
2:9.0.1378-2+deb12u22:9.1.1230-1
Remediation
Event History
Dec 1, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Jan 12, 2024
Data Sourced
via Launchpad·12:00 AM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:35 AM
RemedyDescriptionSeverityAffected Software
Mar 27, 2025
Data Sourced
via Debian·04:24 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2021-3984?
CVE-2021-3984 is a vulnerability in vim that allows for heap-based buffer overflow.
2
How does CVE-2021-3984 affect vim?
CVE-2021-3984 affects vim by allowing an attacker to trigger a heap-based buffer overflow.
3
What is the severity of CVE-2021-3984?
The severity of CVE-2021-3984 is high.
4
How can I fix CVE-2021-3984 in vim?
To fix CVE-2021-3984 in vim, update to version 8.2.3625.
5
Where can I find more information about CVE-2021-3984?
You can find more information about CVE-2021-3984 at the following references: [link1](https://huntr.dev/bounties/b114b5a2-18e2-49f0-b350-15994d71426a), [link2](https://github.com/vim/vim/commit/2de9b7c7c8791da8853a9a7ca9c467867465b655), [link3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNXY7T5OORA7UJIMGSJBGHFMU6UZWS6P/).