CVE-2017-6350
published 2017-02-27CVE-2017-6350: An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree…
PriorityP343critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.39%
87.5th percentile
An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | neovim | < neovim 0.1.7-4 (bookworm) | neovim 0.1.7-4 (bookworm) |
| debian | vim | < neovim 0.1.7-4 (bookworm) | neovim 0.1.7-4 (bookworm) |
| vim | vim | <= 8.0.0377 | — |
| vim | vim | >= 0 < 2:8.0.0197-3 | 2:8.0.0197-3 |
| vim | vim | >= 0 < 2:8.0.0197-3 | 2:8.0.0197-3 |
| vim | vim | >= 0 < 2:8.0.0197-3 | 2:8.0.0197-3 |
| vim | vim | >= 0 < 2:8.0.0197-3 | 2:8.0.0197-3 |
| vim | vim | >= 0 < 2:7.4.1689-3ubuntu1.4 | 2:7.4.1689-3ubuntu1.4 |
| vim | vim | >= 0 < 2:8.0.1453-1ubuntu1.3 | 2:8.0.1453-1ubuntu1.3 |
| vim | vim | >= 0 < 2:7.4.052-1ubuntu3.1+esm1 | 2:7.4.052-1ubuntu3.1+esm1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h6c7-9rqq-5r2p: An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8
ghsa_unreviewed·2022-05-14
CVE-2017-6350 [CRITICAL] CWE-190 GHSA-h6c7-9rqq-5r2p: An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8
An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.
OSV
vim vulnerabilities
osv·2020-03-23·CVSS 7.8
CVE-2017-11109 [HIGH] vim vulnerabilities
vim vulnerabilities
It was discovered that Vim incorrectly handled certain sources.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 12.04 ESM, Ubuntu 14.04 ESM and
Ubuntu 16.04 LTS (CVE-2017-11109)
It was discovered that Vim incorrectly handled certain files.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
(CVE-2017-5953)
It was discovered that Vim incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 16.06 LTS. (CVE-2018-20786)
It was discovered that Vim incorrectly handled certain inputs. An attacker
could possibly use this issue to cause a denial of service or
OSV
CVE-2017-6350: An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8
osv·2017-02-27·CVSS 9.8
CVE-2017-6350 [CRITICAL] CVE-2017-6350: An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8
An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.
Ubuntu
Vim vulnerabilities
vendor_ubuntu·2020-03-23·CVSS 7.8
CVE-2017-11109 [HIGH] Vim vulnerabilities
Title: Vim vulnerabilities
Summary: Several security issues were fixed in Vim.
It was discovered that Vim incorrectly handled certain sources.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 12.04 ESM, Ubuntu 14.04 ESM and
Ubuntu 16.04 LTS (CVE-2017-11109)
It was discovered that Vim incorrectly handled certain files.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
(CVE-2017-5953)
It was discovered that Vim incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 16.06 LTS. (CVE-2018-20786)
It was discovered that Vim incorrectly handled certain inputs. An attacker
c
Red Hat
vim: Integer overflow at an unserialize_uep memory allocation site
vendor_redhat·2017-02-13·CVSS 9.8
CVE-2017-6350 [CRITICAL] CWE-190 vim: Integer overflow at an unserialize_uep memory allocation site
vim: Integer overflow at an unserialize_uep memory allocation site
An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.
An integer overflow flaw was found in the way vim handled tree length values when reading an undo file. This bug could result in vim crashing when trying to process corrupted undo files.
Package: vim (Red Hat Enterprise Linux 5) - Will not fix
Package: vim (Red Hat Enterprise Linux 6) - Will not fix
Package: vim (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2017-6350: neovim - An integer overflow at an unserialize_uep memory allocation site would occur for...
vendor_debian·2017·CVSS 9.8
CVE-2017-6350 [CRITICAL] CVE-2017-6350: neovim - An integer overflow at an unserialize_uep memory allocation site would occur for...
An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.
Scope: local
bookworm: resolved (fixed in 0.1.7-4)
bullseye: resolved (fixed in 0.1.7-4)
forky: resolved (fixed in 0.1.7-4)
sid: resolved (fixed in 0.1.7-4)
trixie: resolved (fixed in 0.1.7-4)
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/96448http://www.securitytracker.com/id/1037949https://github.com/vim/vim/commit/0c8485f0e4931463c0f7986e1ea84a7d79f10c75https://groups.google.com/forum/#%21topic/vim_dev/L_dOHOOiQ5Qhttps://groups.google.com/forum/#%21topic/vim_dev/QPZc0CY9j3Yhttps://security.gentoo.org/glsa/201706-26https://usn.ubuntu.com/4309-1/http://www.securityfocus.com/bid/96448http://www.securitytracker.com/id/1037949https://github.com/vim/vim/commit/0c8485f0e4931463c0f7986e1ea84a7d79f10c75https://groups.google.com/forum/#%21topic/vim_dev/L_dOHOOiQ5Qhttps://groups.google.com/forum/#%21topic/vim_dev/QPZc0CY9j3Yhttps://security.gentoo.org/glsa/201706-26https://usn.ubuntu.com/4309-1/
2017-02-27
Published