PT-2021-5357 · Vim+9 · Vim+9

·

CVE-2021-3903

·

Published

2021-10-24

·

Updated

2025-03-17

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vim (affected versions not specified)
Description The issue is related to a heap-based buffer overflow in the vim editor, which can be exploited by a remote attacker to execute arbitrary commands. This can be achieved by using the -s parameter in the command line to launch a script. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Out of bounds Read

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:9405
ALT-PU-2022-1087
ALT-PU-2022-1711
ALT-PU-2022-1731
ALT-PU-2022-1771
BDU:2021-06187
CVE-2021-3903
DLA-3053-1
INFSA-2024_9405
MGASA-2021-0535
OESA-2021-1421
OPENSUSE-SU-2022_2102-1
RHSA-2024:9405
RHSA-2024_9405
RLSA-2024:9405
SUSE-SU-2022:2102-1
SUSE-SU-2022:4619-1
USN-5147-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Debian
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Vim