First published: Thu Mar 13 2025(Updated: )
Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with Vim and then press 'x' on such a strange filename. The issue has been fixed as of Vim patch v9.1.1198.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Vim | <9.1.1198 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-29768 is medium due to the specific conditions required for exploitation.
To fix CVE-2025-29768, update Vim to version 9.1.1198 or later.
CVE-2025-29768 is a vulnerability in Vim that can lead to potential data loss when handling specially crafted zip files.
Versions of Vim prior to 9.1.1198 are affected by CVE-2025-29768.
Exploitation of CVE-2025-29768 requires the user to open a specially crafted zip file and execute a command within Vim.