Bug 1126750 - (CVE-2018-20786) VUL-1: CVE-2018-20786: vim: libvterm mishandles certain out-of-memory conditions, leading to a denial of service
(CVE-2018-20786)
VUL-1: CVE-2018-20786: vim: libvterm mishandles certain out-of-memory conditi...
Status: NEW
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Minor
: ---
Assigned To: Ismail Dönmez
Security Team bot
https://smash.suse.de/issue/225335/
CVSSv3:SUSE:CVE-2018-20786:3.3:(AV:L/...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-02-25 09:19 UTC by Robert Frohl
Modified: 2020-06-18 02:34 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---
abergmann: needinfo? (ismail)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Frohl 2019-02-25 09:19:30 UTC
CVE-2018-20786

libvterm through 0+bzr726, as used in Vim and other products, mishandles certain
out-of-memory conditions, leading to a denial of service (application crash),
related to screen.c, state.c, and vterm.c.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-20786
https://github.com/vim/vim/issues/3711
https://github.com/vim/vim/commit/cd929f7ba8cc5b6d6dcf35c8b34124e969fed6b8
Comment 1 Robert Frohl 2019-02-25 09:20:54 UTC
Only treating SUSE:SLE-15:Update as affected. In previous version of vim libvterm was not included.