{"id":"USN-4309-1","summary":"vim vulnerabilities","details":"It was discovered that Vim incorrectly handled certain sources.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 12.04 ESM, Ubuntu 14.04 ESM and\nUbuntu 16.04 LTS (CVE-2017-11109)\n\nIt was discovered that Vim incorrectly handled certain files.\nAn attacker could possibly use this issue to execute arbitrary code.\nThis issue only affected Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.\n(CVE-2017-5953)\n\nIt was discovered that Vim incorrectly handled certain inputs.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 16.06 LTS. (CVE-2018-20786)\n\nIt was discovered that Vim incorrectly handled certain inputs. An attacker\ncould possibly use this issue to cause a denial of service or\nexecute arbitrary code. This issue only affected Ubuntu 18.04 LTS and\nUbuntu 19.10. (CVE-2019-20079)\n\nIt was discovered that Vim incorrectly handled certain files. An attacker\ncould possibly use this issue to execute arbitrary code. This issue\nonly affected Ubuntu 12.04 ESM, Ubuntu 14.04 ESM and Ubuntu 16.04 LTS.\n(CVE-2017-6349, CVE-2017-6350)\n","modified":"2026-02-10T04:41:48Z","published":"2020-03-23T14:29:22Z","related":["UBUNTU-CVE-2017-11109","UBUNTU-CVE-2017-5953","UBUNTU-CVE-2017-6349","UBUNTU-CVE-2017-6350","UBUNTU-CVE-2018-20786","UBUNTU-CVE-2019-20079"],"upstream":["CVE-2017-11109","CVE-2017-5953","CVE-2017-6349","CVE-2017-6350","CVE-2018-20786","CVE-2019-20079","UBUNTU-CVE-2017-11109","UBUNTU-CVE-2017-5953","UBUNTU-CVE-2017-6349","UBUNTU-CVE-2017-6350","UBUNTU-CVE-2018-20786","UBUNTU-CVE-2019-20079"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-4309-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2017-5953"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2017-6349"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2017-6350"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2017-11109"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-20786"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2019-20079"}],"affected":[{"package":{"name":"vim","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/vim@2:7.4.052-1ubuntu3.1+esm1?arch=source&distro=trusty/esm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:7.4.052-1ubuntu3.1+esm1"}]}],"versions":["2:7.4.000-1ubuntu2","2:7.4.052-1ubuntu1","2:7.4.052-1ubuntu2","2:7.4.052-1ubuntu3","2:7.4.052-1ubuntu3.1"],"ecosystem_specific":{"binaries":[{"binary_name":"vim","binary_version":"2:7.4.052-1ubuntu3.1+esm1"},{"binary_name":"vim-athena","binary_version":"2:7.4.052-1ubuntu3.1+esm1"},{"binary_name":"vim-common","binary_version":"2:7.4.052-1ubuntu3.1+esm1"},{"binary_name":"vim-gnome","binary_version":"2:7.4.052-1ubuntu3.1+esm1"},{"binary_name":"vim-gtk","binary_version":"2:7.4.052-1ubuntu3.1+esm1"},{"binary_name":"vim-gui-common","binary_version":"2:7.4.052-1ubuntu3.1+esm1"},{"binary_name":"vim-lesstif","binary_version":"2:7.4.052-1ubuntu3.1+esm1"},{"binary_name":"vim-nox","binary_version":"2:7.4.052-1ubuntu3.1+esm1"},{"binary_name":"vim-runtime","binary_version":"2:7.4.052-1ubuntu3.1+esm1"},{"binary_name":"vim-tiny","binary_version":"2:7.4.052-1ubuntu3.1+esm1"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4309-1.json","cves_map":{"cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2017-5953"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"negligible"}],"id":"CVE-2017-6349"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"negligible"}],"id":"CVE-2017-6350"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2017-11109"}],"ecosystem":"Ubuntu:Pro:14.04:LTS"}}},{"package":{"name":"vim","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/vim@2:7.4.1689-3ubuntu1.4?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:7.4.1689-3ubuntu1.4"}]}],"versions":["2:7.4.712-2ubuntu4","2:7.4.826-1ubuntu1","2:7.4.826-1ubuntu2","2:7.4.826-1ubuntu3","2:7.4.963-1ubuntu1","2:7.4.963-1ubuntu4","2:7.4.963-1ubuntu5","2:7.4.1689-3ubuntu1","2:7.4.1689-3ubuntu1.1","2:7.4.1689-3ubuntu1.2","2:7.4.1689-3ubuntu1.3"],"ecosystem_specific":{"binaries":[{"binary_name":"vim","binary_version":"2:7.4.1689-3ubuntu1.4"},{"binary_name":"vim-athena","binary_version":"2:7.4.1689-3ubuntu1.4"},{"binary_name":"vim-athena-py2","binary_version":"2:7.4.1689-3ubuntu1.4"},{"binary_name":"vim-common","binary_version":"2:7.4.1689-3ubuntu1.4"},{"binary_name":"vim-gnome","binary_version":"2:7.4.1689-3ubuntu1.4"},{"binary_name":"vim-gnome-py2","binary_version":"2:7.4.1689-3ubuntu1.4"},{"binary_name":"vim-gtk","binary_version":"2:7.4.1689-3ubuntu1.4"},{"binary_name":"vim-gtk-py2","binary_version":"2:7.4.1689-3ubuntu1.4"},{"binary_name":"vim-gtk3","binary_version":"2:7.4.1689-3ubuntu1.4"},{"binary_name":"vim-gtk3-py2","binary_version":"2:7.4.1689-3ubuntu1.4"},{"binary_name":"vim-gui-common","binary_version":"2:7.4.1689-3ubuntu1.4"},{"binary_name":"vim-nox","binary_version":"2:7.4.1689-3ubuntu1.4"},{"binary_name":"vim-nox-py2","binary_version":"2:7.4.1689-3ubuntu1.4"},{"binary_name":"vim-runtime","binary_version":"2:7.4.1689-3ubuntu1.4"},{"binary_name":"vim-tiny","binary_version":"2:7.4.1689-3ubuntu1.4"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4309-1.json","cves_map":{"cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"negligible"}],"id":"CVE-2017-6349"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"negligible"}],"id":"CVE-2017-6350"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2017-11109"}],"ecosystem":"Ubuntu:16.04:LTS"}}},{"package":{"name":"vim","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/vim@2:8.0.1453-1ubuntu1.3?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:8.0.1453-1ubuntu1.3"}]}],"versions":["2:8.0.0197-4ubuntu5","2:8.0.1144-1ubuntu1","2:8.0.1401-1ubuntu1","2:8.0.1401-1ubuntu2","2:8.0.1401-1ubuntu3","2:8.0.1453-1ubuntu1","2:8.0.1453-1ubuntu1.1"],"ecosystem_specific":{"binaries":[{"binary_name":"vim","binary_version":"2:8.0.1453-1ubuntu1.3"},{"binary_name":"vim-athena","binary_version":"2:8.0.1453-1ubuntu1.3"},{"binary_name":"vim-common","binary_version":"2:8.0.1453-1ubuntu1.3"},{"binary_name":"vim-gnome","binary_version":"2:8.0.1453-1ubuntu1.3"},{"binary_name":"vim-gtk","binary_version":"2:8.0.1453-1ubuntu1.3"},{"binary_name":"vim-gtk3","binary_version":"2:8.0.1453-1ubuntu1.3"},{"binary_name":"vim-gui-common","binary_version":"2:8.0.1453-1ubuntu1.3"},{"binary_name":"vim-nox","binary_version":"2:8.0.1453-1ubuntu1.3"},{"binary_name":"vim-runtime","binary_version":"2:8.0.1453-1ubuntu1.3"},{"binary_name":"vim-tiny","binary_version":"2:8.0.1453-1ubuntu1.3"},{"binary_name":"xxd","binary_version":"2:8.0.1453-1ubuntu1.3"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4309-1.json","cves_map":{"cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2018-20786"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2019-20079"}],"ecosystem":"Ubuntu:18.04:LTS"}}}],"schema_version":"1.7.3"}