CLSA-2021-1639681859
Dashboard / Vulnerabilities / CLSA-2021-1639681859
CLSA-2021-1639681859
Published: 16 Dec 2021Last Modified: 4 Jun 2026
Upstream:
Summary: Fix CVE(s): CVE-2021-3927, CVE-2021-3928
Details: * SECURITY UPDATE: Fix heap-based buffer overflow when reading character past end of line - debian/patches/CVE-2021-3927.patch: Correct the cursor column in src/ex_docmd.c. - CVE-2021-3927 * SECURITY UPDATE: Fix stack-based buffer overflow when reading uninitialized memory when giving spell suggestions - debian/patches/CVE-2021-3928.patch: Check that preword is not empty in src/spell.c. - CVE-2021-3928
Affected packages
Package
Name: vim
Purl: pkg:deb/tuxcare/vim?distro=ubuntu-16.04
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -3:7.4.1689-3ubuntu1.5+tuxcare.els3
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
