CVE-2025-1215

Public on 2025-02-12
Modified on 2025-02-26
Description
A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log leads to memory corruption. It is possible to launch the attack on the local host. Upgrading to version 9.1.1097 is able to address this issue. The patch is identified as c5654b84480822817bb7b69ebc97c174c91185e9. It is recommended to upgrade the affected component.
Severity
Low severity
Low
CVSS v3 Base Score
2.8
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
HAQM Linux 1 vim No Fix Planned
HAQM Linux 2 - Core vim 2025-04-09 ALAS2-2025-2827 Fixed
HAQM Linux 2023 vim 2025-04-09 ALAS2023-2025-932 Fixed

CVSS Scores

Score Type Score Vector
HAQM Linux CVSSv3 2.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
NVD CVSSv2 1.7 AV:L/AC:L/Au:S/C:N/I:N/A:P
NVD CVSSv3 2.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L