CVE-2017-11109Use After Free in VIM

CWE-416Use After Free9 documents7 sources
Severity
7.8HIGHNVD
EPSS
0.3%
top 50.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 8
Latest updateMay 14

Description

Vim 8.0 allows attackers to cause a denial of service (invalid free) or possibly have unspecified other impact via a crafted source (aka -S) file. NOTE: there might be a limited number of scenarios in which this has security relevance.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

debiandebian/vim< vim 2:8.0.0197-5 (bookworm)
Debianvim/vim< 2:8.0.0197-5+3
Ubuntuvim/vim< 2:7.4.1689-3ubuntu1.4+2
NVDvim/vim8.0

🔴Vulnerability Details

3
GHSA
GHSA-hv76-654r-x97r: Vim 82022-05-14
OSV
vim vulnerabilities2020-03-23
OSV
CVE-2017-11109: Vim 82017-07-08

📋Vendor Advisories

3
Ubuntu
Vim vulnerabilities2020-03-23
Red Hat
vim: Use-after-free via crafted file2017-07-07
Debian
CVE-2017-11109: vim - Vim 8.0 allows attackers to cause a denial of service (invalid free) or possibly...2017

💬Community

2
Bugzilla
CVE-2017-11109 vim: Use-after-free via crafted file [fedora-all]2017-07-19
Bugzilla
CVE-2017-11109 vim: Use-after-free via crafted file2017-07-19