glvd logo
glvd logo
Garden Linux Vulnerability Database
CVE Description

"Vim is an open source, command line text editor. Prior to version 9.1.1552, a path traversal issue in Vim\u2019s tar.vim plugin can allow overwriting of arbitrary files when opening specially crafted tar archives. Impact is low because this exploit requires direct user interaction. However, successfully exploitation can lead to overwriting sensitive files or placing executable code in privileged locations, depending on the permissions of the process editing the archive. The victim must edit such a file using Vim which will reveal the filename and the file content, a careful user may suspect some strange things going on. Successful exploitation could results in the ability to execute arbitrary commands on the underlying operating system. Version 9.1.1552 contains a patch for the vulnerability."

Metadata

Vulnerability Status Published Date Modified Date Ingested Date
Modified 2025-07-15T21:15:34.347 2025-11-04T22:16:27.173 2025-11-04 22:16:27.173+00

CVSS Scores

CVSS Version Base Score DEB CVSS Severity Vector String
3.1 4.1 MEDIUM CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:L

Affected Linux Images

Distro Version Source Package Package Version Is Vulnerable Is fixed in Version
gardenlinux kvm-cilium-k3s-1605.0-490ed850 vim 2:9.1.0496-1+b1 true 2:9.1.1829-1
gardenlinux kvm-gardener-1605.0-490ed850 vim 2:9.1.0496-1+b1 true 2:9.1.1829-1
gardenlinux metal-cilium-k3s-osc-vhost-1605.0-490ed850 vim 2:9.1.0496-1+b1 true 2:9.1.1829-1
gardenlinux metal-cilium-k3s-osc-1605.0-490ed850 vim 2:9.1.0496-1+b1 true 2:9.1.1829-1
gardenlinux kvm-cilium-k3s-1721.0-9802b525 vim 2:9.1.0861-1 true 2:9.1.1829-1
gardenlinux kvm-gardener-1721.0-9802b525 vim 2:9.1.0861-1 true 2:9.1.1829-1
gardenlinux metal-cilium-k3s-osc-ucode-vhost-1721.0-9802b525 vim 2:9.1.0861-1 true 2:9.1.1829-1
gardenlinux metal-cilium-k3s-osc-ucode-1721.0-9802b525 vim 2:9.1.0861-1 true 2:9.1.1829-1
debian_linux 13 vim 2:9.1.1230-2 true
debian_linux 12 vim 2:9.0.1378-2+deb12u2 true 2:9.1.1829-1
gardenlinux metal-cilium-k3s-osc-router-ucode-1721.0-9802b525 vim 2:9.1.0861-1 true 2:9.1.1829-1
gardenlinux kvm-cilium-k3s-1862.0-6be879c6 vim 2:9.1.1230-1 true 2:9.1.1829-1
gardenlinux kvm-gardener-1862.0-6be879c6 vim 2:9.1.1230-1 true 2:9.1.1829-1
gardenlinux pt-gardener-nvgpu-1862.0-6be879c6 vim 2:9.1.1230-1 true 2:9.1.1829-1
gardenlinux metal-cilium-k3s-osc-ucode-vhost-1862.0-6be879c6 vim 2:9.1.1230-1 true 2:9.1.1829-1
gardenlinux metal-cilium-k3s-osc-ucode-1862.0-6be879c6 vim 2:9.1.1230-1 true 2:9.1.1829-1
gardenlinux metal-cilium-k3s-osc-router-ucode-1862.0-6be879c6 vim 2:9.1.1230-1 true 2:9.1.1829-1
debian_linux 14 vim 2:9.1.2103-1 false 2:9.1.1829-1