CVE-2025-29768: Vim vulnerable to potential data loss with zip.vim and special crafted zip files
Vim vulnerable to potential data loss with zip.vim and special crafted zip files
Other sources
Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with Vim and then press 'x' on such a strange filename. The issue has been fixed as of Vim patch v9.1.1198.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Vimto a version that resolves this vulnerability.Fixed in 9.1.1198Patch v9.1.1198
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29768?
The severity of CVE-2025-29768 is medium due to the specific conditions required for exploitation.
How do I fix CVE-2025-29768?
To fix CVE-2025-29768, update Vim to version 9.1.1198 or later.
What type of vulnerability is CVE-2025-29768?
CVE-2025-29768 is a vulnerability in Vim that can lead to potential data loss when handling specially crafted zip files.
Which versions of Vim are affected by CVE-2025-29768?
Versions of Vim prior to 9.1.1198 are affected by CVE-2025-29768.
What exploitation conditions are required for CVE-2025-29768?
Exploitation of CVE-2025-29768 requires the user to open a specially crafted zip file and execute a command within Vim.