Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2025-24014

Published: January 22, 2025Last modified: February 14, 2025

Description

Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim typically doesn't show a screen and just operates silently in batch mode. However, it is still possible to trigger the function that handles the scrolling of a gui version of Vim by feeding some binary characters to Vim. The function that handles the scrolling however may be triggering a redraw, which will access the ScreenLines pointer, even so this variable hasn't been allocated (since there is no screen). This vulnerability is fixed in 9.1.1043.

Severity score breakdown

ParameterValue
Base score4.2
Attack VectorLOCAL
Attack complexityHIGH
Privileges requiredLOW
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactLOW
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSvimFixed (9.1.1105-r0)
StreamvimFixed (9.1.1105-r0)

References

ON THIS PAGE