A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log leads to memory corruption. It is possible to launch the attack on the local host. Upgrading to version 9.1.1097 is able to address this issue. The patch is identified as c5654b84480822817bb7b69ebc97c174c91185e9. It is recommended to upgrade the affected component.
CVSS Details
- CVSS 4.0 Base Score: 2.4 (LOW)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 2.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade vim-debuginfoUpgrade vim-filesystemUpgrade vim-dataUpgrade vim-X11Upgrade vim-commonUpgrade vim-minimalUpgrade vim-enhancedUpgrade xxd | Apr 17, 2025 | Feb 12, 2025 |
| Amazon_linux_2023 | — | Upgrade vim-commonUpgrade vim-minimal-debuginfoUpgrade xxdUpgrade vim-debuginfoUpgrade xxd-debuginfoUpgrade vim-enhanced-debuginfoUpgrade vim-dataUpgrade vim-enhancedUpgrade vim-debugsourceUpgrade vim-filesystemUpgrade vim-minimalUpgrade vim-default-editor | Apr 15, 2025 | Feb 12, 2025 |
| Debian | — | No solution existsUpgrade vim | May 15, 2025 | Feb 12, 2025 |
| Dell Powerstore Dsa2025342 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Sep 2, 2025 |
| Dell Powerstore Dsa2026039 | — | Upgrade Dell PowerStoreOS to the latest version | Jan 13, 2026 | Jan 6, 2026 |
| Huawei Euleros 2_0_sp10 | — | Upgrade vim-commonUpgrade vim-filesystemUpgrade vim-enhancedUpgrade vim-minimal | May 13, 2025 | Feb 12, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade vim-enhancedUpgrade vim-minimalUpgrade vim-filesystemUpgrade vim-common | Jun 13, 2025 | Feb 12, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade vim-filesystemUpgrade vim-minimalUpgrade vim-enhancedUpgrade vim-common | Jun 11, 2025 | Feb 12, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade vim-commonUpgrade vim-filesystemUpgrade vim-enhancedUpgrade vim-minimal | Jun 11, 2025 | Feb 12, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 12, 2025 |
| Suse | — | Upgrade vim-dataUpgrade gvimUpgrade vimUpgrade xxdUpgrade vim-smallUpgrade vim-data-common | Feb 28, 2025 | Feb 12, 2025 |
| Ubuntu | — | Upgrade vimUpgrade vim (Ubuntu Pro) | Apr 8, 2025 | Feb 12, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 2, 2025 | Feb 12, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub