CVE-2017-6350
Gentoo Linux Security Advisory 201706-26
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.
Un desbordamiento de entero en un sitio de asignación de memoria unserialize_uep ocurriría para vim en versiones anteriores al parche 8.0.0378, si no valida correctamente los valores de longitud del arból de decisión, al leer un archivo desecho corrompido, lo que puede resultar en un desbordamiento de búfer.
Multiple vulnerabilities have been found in Vim and gVim, the worst of which might allow remote attackers to execute arbitrary code. Versions less than 8.0.0386 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-02-26 CVE Reserved
- 2017-02-27 CVE Published
- 2024-08-05 CVE Updated
- 2025-04-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-190: Integer Overflow or Wraparound
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/96448 | Vdb Entry | |
http://www.securitytracker.com/id/1037949 | Vdb Entry | |
https://groups.google.com/forum/#%21topic/vim_dev/L_dOHOOiQ5Q | X_refsource_misc | |
https://groups.google.com/forum/#%21topic/vim_dev/QPZc0CY9j3Y | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/vim/vim/commit/0c8485f0e4931463c0f7986e1ea84a7d79f10c75 | 2023-11-07 |
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/201706-26 | 2023-11-07 | |
https://usn.ubuntu.com/4309-1 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vim Search vendor "Vim" | Vim Search vendor "Vim" for product "Vim" | <= 8.0.0377 Search vendor "Vim" for product "Vim" and version " <= 8.0.0377" | - |
Affected
|