REDHAT-BUG-2455542: Path Traversal
Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in 9.2.0280.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Vim zip.vim pluginto a version that resolves this vulnerability.Fixed in 9.2.0280
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2455542?
The severity of REDHAT-BUG-2455542 is medium with a score of 4.
What does REDHAT-BUG-2455542 affect?
REDHAT-BUG-2455542 affects the Vim text editor, specifically the zip.vim plugin.
How do I fix REDHAT-BUG-2455542?
To fix REDHAT-BUG-2455542, upgrade Vim to version 9.2.0280 or later.
What type of vulnerability is REDHAT-BUG-2455542?
REDHAT-BUG-2455542 is classified as a path traversal vulnerability.
What issue is circumvented by the vulnerability in REDHAT-BUG-2455542?
The vulnerability in REDHAT-BUG-2455542 allows overwriting of arbitrary files and circumvents the previous fix for CVE-2025-53906.