https://seclists.org/oss-sec/2024/q2/233: [vim-security] buffer-overlow in xxd with colod output < v9.1.0404
Published May 10, 2024
·Updated
Affected Software
1 affected component
vim Vim<9.1.0404
Frequently Asked Questions
1
What is the severity of CVE-2024-2340?
The severity of CVE-2024-2340 is classified as low.
2
How do I fix CVE-2024-2340?
To fix CVE-2024-2340, update Vim to the latest version that has patched this vulnerability.
3
What software is affected by CVE-2024-2340?
CVE-2024-2340 affects Vim versions lower than 9.1.0404.
4
What is the nature of CVE-2024-2340?
CVE-2024-2340 is a buffer overflow vulnerability that occurs when outputting colored hexdumps using specific command line flags.
5
Is there a workaround for CVE-2024-2340?
A temporary workaround for CVE-2024-2340 is to avoid using the -R flag with xxd while outputting colored output.