https://seclists.org/oss-sec/2025/q1/211: [vim-security] potential data loss with zip.vim and special crafted zip files in Vim < v9.1.1198
Published Mar 13, 2025
·Updated
Affected Software
1 affected component
vim Vim<9.1.1198
Frequently Asked Questions
1
What is the severity of CVE-2025-XXXX?
The severity of CVE-2025-XXXX is classified as high due to potential data loss.
2
How do I fix CVE-2025-XXXX?
To fix CVE-2025-XXXX, update Vim to the latest version that includes the patch addressing this vulnerability.
3
What versions of Vim are affected by CVE-2025-XXXX?
Vim versions prior to v9.1.1198 are affected by CVE-2025-XXXX.
4
What are the consequences of CVE-2025-XXXX?
The consequences of CVE-2025-XXXX can include potential data loss when extracting specially crafted zip files.
5
Is there a workaround for CVE-2025-XXXX until I can update Vim?
A possible workaround for CVE-2025-XXXX is to avoid using zip.vim for extracting zip files until you can apply the update.