https://seclists.org/oss-sec/2025/q1/209: [vim-security] potential data loss with zip.vim and special crafted zip files in Vim < v9.1.1198
Published Mar 13, 2025
·Updated
Affected Software
1 affected component
vim Vim<9.1.1198
Frequently Asked Questions
1
What is the severity of CVE-2025-XXXX?
The severity of CVE-2025-XXXX is classified as high due to the potential for data loss.
2
How do I fix CVE-2025-XXXX?
To fix CVE-2025-XXXX, upgrade Vim to version 9.1.1198 or later.
3
What is CVE-2025-XXXX related to?
CVE-2025-XXXX is related to potential data loss when using zip.vim with specially crafted zip files in Vim versions prior to 9.1.1198.
4
Which versions of Vim are affected by CVE-2025-XXXX?
Vim versions earlier than 9.1.1198 are affected by CVE-2025-XXXX.
5
What should I do if I cannot upgrade due to dependencies related to CVE-2025-XXXX?
If unable to upgrade, consider implementing additional input validation and file handling precautions as a temporary measure against CVE-2025-XXXX.