CVE-2021-4136
Published: 19 December 2021
vim is vulnerable to Heap-based Buffer Overflow
Priority
CVSS 3 base score: 7.8
Status
Package | Release | Status |
---|---|---|
vim Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(code not present)
|
focal |
Not vulnerable
(code not present)
|
|
hirsute |
Ignored
(reached end-of-life)
|
|
impish |
Needed
|
|
jammy |
Not vulnerable
(2:8.2.3995-1ubuntu2)
|
|
trusty |
Not vulnerable
(code not present)
|
|
upstream |
Released
(8.2.3847)
|
|
xenial |
Not vulnerable
(code not present)
|
Notes
Author | Note |
---|---|
ccdm94 | introduced by commit 2949cfdbe433 (>= 8.2.2257). |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4136
- https://huntr.dev/bounties/5c6b93c1-2d27-4e98-a931-147877b8c938
- https://github.com/vim/vim/commit/605ec91e5a7330d61be313637e495fa02a6dc264
- NVD
- Launchpad
- Debian