USN-7048-1: Vim vulnerability
Published Oct 1, 2024
·Updated
Suyue Guo discovered that Vim incorrectly handled memory when flushing the typeahead buffer, leading to heap-buffer-overflow. An attacker could possibly use this issue to cause a denial of service.
Affected Software
10 affected componentsFixes available
All of the following
ubuntu/vim<2:9.1.0016-1ubuntu7.3
2:9.1.0016-1ubuntu7.3
Ubuntu Ubuntu=24.04
All of the following
ubuntu/vim<2:8.2.3995-1ubuntu2.19
2:8.2.3995-1ubuntu2.19
Ubuntu Ubuntu=22.04
All of the following
ubuntu/vim<2:8.1.2269-1ubuntu5.25
2:8.1.2269-1ubuntu5.25
Ubuntu Ubuntu=20.04
All of the following
ubuntu/vim<2:8.0.1453-1ubuntu1.13+esm10
2:8.0.1453-1ubuntu1.13+esm10
Ubuntu Ubuntu=18.04
All of the following
ubuntu/vim<2:7.4.1689-3ubuntu1.5+esm25
2:7.4.1689-3ubuntu1.5+esm25
Ubuntu Ubuntu=16.04
Event History
Oct 1, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7048-1?
USN-7048-1 is classified as having a medium severity level as it can lead to a denial of service.
2
How do I fix USN-7048-1?
To fix USN-7048-1, upgrade to the corrected versions of Vim specified in the advisory.
3
What versions of Vim are affected by USN-7048-1?
USN-7048-1 affects multiple versions of Vim across Ubuntu 16.04, 18.04, 20.04, 22.04, and 24.04.
4
Can USN-7048-1 be exploited remotely?
While USN-7048-1 does not indicate direct remote exploitation, an attacker may exploit it to cause a denial of service.
5
Is a system restart required after applying the fix for USN-7048-1?
Generally, a system restart is not required after applying the updated version of Vim for USN-7048-1.