Vulnerability Description
libvterm through 0+bzr726, as used in Vim and other products, mishandles certain out-of-memory conditions, leading to a denial of service (application crash), related to screen.c, state.c, and vterm.c.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Leonerd | Libvterm | <= 0\+bzr726 |
Related Weaknesses (CWE)
References
- https://github.com/vim/vim/commit/cd929f7ba8cc5b6d6dcf35c8b34124e969fed6b8PatchThird Party Advisory
- https://github.com/vim/vim/issues/3711ExploitThird Party Advisory
- https://usn.ubuntu.com/4309-1/
- https://github.com/vim/vim/commit/cd929f7ba8cc5b6d6dcf35c8b34124e969fed6b8PatchThird Party Advisory
- https://github.com/vim/vim/issues/3711ExploitThird Party Advisory
- https://usn.ubuntu.com/4309-1/
FAQ
What is CVE-2018-20786?
CVE-2018-20786 is a vulnerability with a CVSS score of 7.5 (HIGH). libvterm through 0+bzr726, as used in Vim and other products, mishandles certain out-of-memory conditions, leading to a denial of service (application crash), related to screen.c, state.c, and vterm.c...
How severe is CVE-2018-20786?
CVE-2018-20786 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-20786?
Check the references section above for vendor advisories and patch information. Affected products include: Leonerd Libvterm.