USN-5147-1
Dashboard / Vulnerabilities / USN-5147-1
USN-5147-1
Summary: vim vulnerabilities
Details: It was discovered that Vim incorrectly handled permissions on the .swp file. A local attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 14.04 ESM. (CVE-2017-17087) It was discovered that Vim incorrectly handled restricted mode. A local attacker could possibly use this issue to bypass restricted mode and execute arbitrary commands. Note: This update only makes executing shell commands more difficult. Restricted mode should not be considered a complete security measure. This issue only affected Ubuntu 14.04 ESM. (CVE-2019-20807) Brian Carpenter discovered that vim incorrectly handled memory when opening certain files. If a user was tricked into opening a specially crafted file, a remote attacker could crash the application, leading to a denial of service, or possible execute arbitrary code with user privileges. This issue only affected Ubuntu 20.04 LTS, Ubuntu 21.04 and Ubuntu 21.10. (CVE-2021-3872) It was discovered that vim incorrectly handled memory when opening certain files. If a user was tricked into opening a specially crafted file, a remote attacker could crash the application, leading to a denial of service, or possible execute arbitrary code with user privileges. (CVE-2021-3903) It was discovered that vim incorrectly handled memory when opening certain files. If a user was tricked into opening a specially crafted file, a remote attacker could crash the application, leading to a denial of service, or possible execute arbitrary code with user privileges. (CVE-2021-3927) It was discovered that vim incorrectly handled memory when opening certain files. If a user was tricked into opening a specially crafted file, a remote attacker could crash the application, leading to a denial of service, or possible execute arbitrary code with user privileges. (CVE-2021-3928)
References: https://ubuntu.com/security/notices/USN-5147-1, https://ubuntu.com/security/CVE-2017-17087, https://ubuntu.com/security/CVE-2019-20807, https://ubuntu.com/security/CVE-2021-3872, https://ubuntu.com/security/CVE-2021-3903, https://ubuntu.com/security/CVE-2021-3927, https://ubuntu.com/security/CVE-2021-3928
Affected packages
Package
Name: vim
Purl: pkg:deb/ubuntu/vim?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
