vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer overflow.
References
Configurations
History
No history.
Information
Published : 2017-02-10 07:59
Updated : 2023-11-07 02:49
NVD link : CVE-2017-5953
Mitre link : CVE-2017-5953
CVE.ORG link : CVE-2017-5953
JSON object : View
Products Affected
vim
- vim
CWE
CWE-190
Integer Overflow or Wraparound