USN-5247-1: Vim vulnerabilities
It was discovered that vim incorrectly handled parsing of filenames in its search functionality. If a user was tricked into opening a specially crafted file, an attacker could crash the application, leading to a denial of service. This issue only affected Ubuntu 21.10. (CVE-2021-3973) It was discovered that vim incorrectly handled memory when opening and searching the contents of certain files. If a user was tricked into opening a specially crafted file, an attacker could crash the application, leading to a denial of service, or possibly achieve code execution with user privileges. This issue only affected Ubuntu 20.04 LTS and Ubuntu 21.10. (CVE-2021-3974) It was discovered that vim incorrectly handled memory when opening and editing certain files. If a user was tricked into opening a specially crafted file, an attacker could crash the application, leading to a denial of service, or possibly achieve code execution with user privileges. (CVE-2021-3984) It was discovered that vim incorrectly handled memory when opening and editing certain files. If a user was tricked into opening a specially crafted file, an attacker could crash the application, leading to a denial of service, or possibly achieve code execution with user privileges. (CVE-2021-4019) It was discovered that vim incorrectly handled memory when opening and editing certain files. If a user was tricked into opening a specially crafted file, an attacker could crash the application, leading to a denial of service, or possibly achieve code execution with user privileges.(CVE-2021-4069)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this advisory?
The vulnerability ID for this advisory is CVE-2021-3973.
Which version of Ubuntu is affected by this vulnerability?
This vulnerability only affects Ubuntu 21.10.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by tricking a user into opening a specially crafted file, which can crash the application and lead to a denial of service.
What is the remedy for this vulnerability in Ubuntu 21.10?
The remedy for this vulnerability in Ubuntu 21.10 is to upgrade to vim version 2:8.2.2434-3ubuntu3.2 or later.
Are there any additional references for this vulnerability?
Yes, you can find more information about this vulnerability in the following references: [link1](https://ubuntu.com/security/CVE-2021-3974), [link2](https://ubuntu.com/security/CVE-2021-3984), [link3](https://ubuntu.com/security/CVE-2021-4019).