CVE-2021-4187
Published: 29 December 2021
vim is vulnerable to Use After Free
Priority
CVSS 3 base score: 7.8
Status
Package | Release | Status |
---|---|---|
vim Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(code not present)
|
focal |
Not vulnerable
(code not present)
|
|
hirsute |
Ignored
(reached end-of-life)
|
|
impish |
Needed
|
|
jammy |
Not vulnerable
(2:8.2.3995-1ubuntu2)
|
|
trusty |
Not vulnerable
(code not present)
|
|
upstream |
Released
(v8.2.3923)
|
|
xenial |
Not vulnerable
(code not present)
|
Notes
Author | Note |
---|---|
ccdm94 | introduced by commit 04b12697838 (>= 8.2.0695). |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4187
- https://huntr.dev/bounties/a8bee03a-6e2e-43bf-bee3-4968c5386a2e
- https://github.com/vim/vim/commit/4bf1006cae7e87259ccd5219128c3dba75774441
- NVD
- Launchpad
- Debian