CVE-2019-20079Use After Free in VIM

CWE-416Use After Free10 documents8 sources
Severity
7.8HIGHNVD
EPSS
0.8%
top 25.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30
Latest updateMay 24

Description

The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages7 packages

NVDvim/vim8.1.21218.1.2136
debiandebian/vim< vim 2:8.1.2136-1 (bookworm)
Debianvim/vim< 2:8.1.2136-1+3
Ubuntuvim/vim< 2:7.4.1689-3ubuntu1.4+2

Also affects: Ubuntu Linux 12.04, 14.04, 16.04, 18.04, 19.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-m46q-8w93-c76v: The autocmd feature in window2022-05-24
OSV
vim vulnerabilities2020-03-23
OSV
CVE-2019-20079: The autocmd feature in window2019-12-30

📋Vendor Advisories

4
Ubuntu
Vim vulnerabilities2020-03-23
Microsoft
The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory.2019-12-10
Red Hat
vim: Use after free in window.c2019-10-10
Debian
CVE-2019-20079: vim - The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory.2019

💬Community

2
Bugzilla
CVE-2019-20079 vim: Use after free in window.c [fedora-all]2020-01-09
Bugzilla
CVE-2019-20079 vim: Use after free in window.c2020-01-09