• CVE-2025-29768

发布时间: 2025年3月29日

修改时间: 2025年3月29日

概要

Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with Vim and then press 'x' on such a strange filename. The issue has been fixed as of Vim patch v9.1.1198.

CVSS v3 指标

NVD openEuler
Confidentiality Low Low
Attack Vector Local Local
CVSS评分 4.4 4.4
Attack Complexity Low Low
Privileges Required None None
Scope Unchanged Unchanged
Integrity Low Low
User Interaction Required Required
Availability None None

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2462 vim security update 2025年5月1日

影响产品

产品 状态
KY3.5.3 vim Fixed
V6 vim Fixed
KY3.4-5A vim Fixed
KY3.5.2 vim Fixed