CVE-2021-4173
Published: 27 December 2021
vim is vulnerable to Use After Free
Priority
CVSS 3 base score: 7.8
Status
Package | Release | Status |
---|---|---|
vim Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(code not present)
|
focal |
Not vulnerable
(code not present)
|
|
hirsute |
Ignored
(reached end-of-life)
|
|
impish |
Needed
|
|
jammy |
Not vulnerable
(2:8.2.3995-1ubuntu2)
|
|
trusty |
Not vulnerable
(code not present)
|
|
upstream |
Released
(8.2.3902)
|
|
xenial |
Not vulnerable
(code not present)
|
Notes
Author | Note |
---|---|
ccdm94 | introduced by commit 04b12697838 (>= 8.2.0695). The patch for this CVE is related to the patch for CVE-2022-0156. |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4173
- https://huntr.dev/bounties/a1b236b9-89fb-4ccf-9689-ba11b471e766
- https://github.com/vim/vim/commit/9c23f9bb5fe435b28245ba8ac65aa0ca6b902c04
- NVD
- Launchpad
- Debian