Integer overflow - CVE-2017-6349
Published: February 27, 2017 / Updated: August 4, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.
Affected software
Gentoo Linux
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Fedora
neovim (Alpine package)
vim
vim-data
vim-data-common
gvim
gvim-debuginfo
vim-debuginfo
vim-debugsource
How to mitigate CVE-2017-6349
vim-data - update to 9.0.0814-17.9.1
vim-data-common - update to 9.0.0814-17.9.1
gvim - update to 9.0.0814-17.9.1
gvim-debuginfo - update to 9.0.0814-17.9.1
vim - update to 9.0.0814-17.9.1
vim-debuginfo - update to 9.0.0814-17.9.1
vim-debugsource - update to 9.0.0814-17.9.1
External References
- http://www.securityfocus.com/bid/96451
- http://www.securitytracker.com/id/1037949
- https://github.com/vim/vim/commit/3eb1637b1bba19519885dd6d377bd5596e91d22c
- https://groups.google.com/forum/#!topic/vim_dev/LAgsTcdSfNA
- https://groups.google.com/forum/#!topic/vim_dev/QPZc0CY9j3Y
- https://security.gentoo.org/glsa/201706-26
- https://usn.ubuntu.com/4309-1/