CVE-2021-4019: Heap-based Buffer Overflow in vim/vim
Published Dec 1, 2021
·Updated
Last updated 21 August 2024
Other sources
vim is vulnerable to Heap-based Buffer Overflow
Affected Software
8 affected componentsFixes available
vim Vim<8.2.3669
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Debian Debian Linux=9.0
Debian Debian Linux=10.0
debian/vim<=2:8.2.2434-3+deb11u1
2:8.2.2434-3+deb11u32:9.0.1378-2+deb12u22:9.1.1230-1
Neovim Neovim<0.7.0
Debian Debian Linux=11.0
Remediation
Event History
Dec 1, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Jan 12, 2024
Data Sourced
via Launchpad·12:00 AM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:35 AM
RemedyDescriptionSeverityAffected Software
Mar 27, 2025
Data Sourced
via Debian·04:24 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2021-4019.
2
What is the title of this vulnerability?
The title of this vulnerability is 'vim is vulnerable to Heap-based Buffer Overflow'.
3
What software is affected by this vulnerability?
The software affected by this vulnerability is vim.
4
What is the severity of this vulnerability?
The severity of this vulnerability depends on various factors such as the attacker's skill level and the system's configuration.
5
How do I fix this vulnerability?
To fix this vulnerability, update the vim software to version 2:8.0.1453-1ubuntu1.8 or higher if you are using Ubuntu, or version 2:8.1.0875-5+deb10u5 or higher if you are using Debian.