Alerts This Week
Warning Icon 1 1,153
Alerts This Week
Warning Icon 1 1,153

Ubuntu 14.04 LTS USN-6965-1: Moderate Vim Denial Of Service

ubuntu
Calendar Grey August 21, 2024
Dist Ubuntu Esm H88
Multiple vulnerabilities addressed in Vim for Ubuntu, resulting in possible service interruptions and risks of arbitrary code execution.
Several security issues were fixed in Vim.

Summary

Several security issues were fixed in Vim.

Software Description:

- vim: Vi IMproved - enhanced vi editor

Details:

It was discovered that vim incorrectly handled parsing of filenames in its

search functionality. If a user was tricked into opening a specially

crafted file, an attacker could crash the application, leading to a denial

of service. (CVE-2021-3973)

It was discovered that vim incorrectly handled memory when opening and

searching the contents of certain files. If a user was tricked into opening

a specially crafted file, an attacker could crash the application, leading

to a denial of service, or possibly achieve code execution with user

privileges. (CVE-2021-3974)

It was discovered that vim incorrectly handled memory when opening and

editing certain files. If a user was tricked into opening a specially

crafted file, an attacker could crash the application, leading to a denial

of service, or possibly achieve code execution with user privileges.

(CV...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS
   vim                             2:7.4.052-1ubuntu3.1+esm17
                                   Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6965-1

CVE-2021-3973, CVE-2021-3974, CVE-2021-3984, CVE-2021-4019,

CVE-2021-4069

Ubuntu Security Notice USN-6965-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here