#VU96466 Heap-based buffer overflow in Vim - CVE-2024-43790
Published: August 22, 2024 / Updated: August 26, 2024
Vim
Vim.org
Description
The vulnerability allows a remote attacker to crash the application.
The vulnerability exists due to boundary error within the do_search() function when performing a search and displaying the search-count message is disabled. A remote attacker can trick the victim to open a specially crafted file and use a specially crafted payload to search information, trigger a heap-based buffer overflow and crash the editor.