Integer overflow in Vim - CVE-2017-6350

 

Integer overflow in Vim - CVE-2017-6350

Published: August 3, 2020


Vulnerability identifier: #VU33141
CSH Severity: Medium
CVSS v4: 5.4 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6350
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow when reading undo files. A remote attacker can trick the victim to open a specially crafted undo file, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Vim
Amazon Linux AMI
Gentoo Linux
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Fedora
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
WebSVN
EMC Cloud Tiering Appliance
neovim (Alpine package)
vim
vim-data
vim-data-common
gvim
gvim-debuginfo
vim-debuginfo
vim-debugsource
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
Dell Secure Connect Gateway

How to mitigate CVE-2017-6350

Install updates from vendor's website.

Vim - update to 8.0.0378
neovim (Alpine package) - update to 0.2.2-r1
EMC ViPR SRM - update to 4.9.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
Dell Secure Connect Gateway - update to 5.14.00.16
vim - addressed in versions 8.0.386-1.fc24, 8.0.386-1.fc25
vim-data - update to 9.0.0814-17.9.1
vim-data-common - update to 9.0.0814-17.9.1
gvim - update to 9.0.0814-17.9.1
gvim-debuginfo - update to 9.0.0814-17.9.1
vim - update to 9.0.0814-17.9.1
vim-debuginfo - update to 9.0.0814-17.9.1
vim-debugsource - update to 9.0.0814-17.9.1
EMC Cloud Tiering Appliance - update to 13.1.0.2.29

External References

Related Security Bulletins