PT-2026-52477 · Vim+3 · Vim+3
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Vim versions prior to 9.2.0671
Description
When opening a file encrypted using the VimCrypt04! or VimCrypt05! methods (which utilize xchacha20poly1305 and require the +sodium feature), an unsigned length calculation underflows if the file body is shorter than a single libsodium secretstream header. This leads to a decryption call that reads beyond the end of the input buffer, resulting in a crash of the application.
Recommendations
Update to version 9.2.0671.
Exploit
Fix
DoS
Integer Underflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Red Os
Ubuntu
Vim