Integer overflow - CVE-2017-5953

 

Integer overflow - CVE-2017-5953

Published: February 10, 2017 / Updated: August 4, 2020


Vulnerability identifier: #VU33443
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5953
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer overflow.


Affected software

Arch Linux
Amazon Linux AMI
Gentoo Linux
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Fedora
neovim (Alpine package)
vim
vim-data
vim-data-common
gvim
gvim-debuginfo
vim-debuginfo
vim-debugsource

How to mitigate CVE-2017-5953

Install update from vendor's website.

vim - addressed in versions 8.0.324-1.fc24, 8.0.324-1.fc25
vim-data - update to 9.0.0814-17.9.1
vim-data-common - update to 9.0.0814-17.9.1
gvim - update to 9.0.0814-17.9.1
gvim-debuginfo - update to 9.0.0814-17.9.1
vim - update to 9.0.0814-17.9.1
vim-debuginfo - update to 9.0.0814-17.9.1
vim-debugsource - update to 9.0.0814-17.9.1

External References

Related Security Bulletins