vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer overflow.
References
Configurations
History
No history.
Information
Published : 2017-02-10 07:59
Updated : 2025-04-20 01:37
NVD link : CVE-2017-5953
Mitre link : CVE-2017-5953
CVE.ORG link : CVE-2017-5953
JSON object : View
Products Affected
vim
- vim
CWE
CWE-190
Integer Overflow or Wraparound