CVE-2025-1215

Description

A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log leads to memory corruption. It is possible to launch the attack on the local host. Upgrading to version 9.1.1097 is able to address this issue. The patch is identified as c5654b84480822817bb7b69ebc97c174c91185e9. It is recommended to upgrade the affected component.

Risk Information

Base Score
2.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
EPSS Score
Exploitation Probability
0.382

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2025-1215 are affected in Vim 9.1.1096Windows
SUSE-SU-2025:0723-1(Basesystem Module 15-SP6) vim-data-9.1.1101-150500.20.21.1.noarch.rpmLinux
SUSE-SU-2025:0723-1(Basesystem Module 15-SP6) vim-9.1.1101-150500.20.21.1.x86_64.rpmLinux
SUSE-SU-2025:0723-1(Desktop Applications Module 15-SP6) gvim-debuginfo-9.1.1101-150500.20.21.1.x86_64.rpmLinux
SUSE-SU-2025:0723-1(Basesystem Module 15-SP6) vim-data-common-9.1.1101-150500.20.21.1.noarch.rpmLinux
SUSE-SU-2025:0723-1(Basesystem Module 15-SP6) vim-small-debuginfo-9.1.1101-150500.20.21.1.x86_64.rpmLinux
SUSE-SU-2025:0723-1(Basesystem Module 15-SP6) vim-small-9.1.1101-150500.20.21.1.x86_64.rpmLinux
SUSE-SU-2025:0723-1(Basesystem Module 15-SP6) vim-debugsource-9.1.1101-150500.20.21.1.x86_64.rpmLinux
SUSE-SU-2025:0723-1(Desktop Applications Module 15-SP6) gvim-9.1.1101-150500.20.21.1.x86_64.rpmLinux
SUSE-SU-2025:0723-1(Basesystem Module 15-SP6) vim-debuginfo-9.1.1101-150500.20.21.1.x86_64.rpmLinux
Vi IMproved - enhanced vi editor (USN-7419-1) vim_8.1.2269-1ubuntu5.32_amd64.debLinux
Vi IMproved - enhanced vi editor (USN-7419-1) vim_8.1.2269-1ubuntu5.32_i386.debLinux
Vi IMproved - enhanced vi editor (USN-7419-1) vim_8.2.3995-1ubuntu2.24_amd64.debLinux
Vi IMproved - enhanced vi editor (USN-7419-1) vim_8.2.3995-1ubuntu2.24_i386.debLinux
Vi IMproved - enhanced vi editor (USN-7419-1) vim_9.1.0016-1ubuntu7.8_amd64.debLinux
Vi IMproved - enhanced vi editor (USN-7419-1) vim_9.1.0016-1ubuntu7.8_i386.debLinux
Vi IMproved - enhanced vi editor (USN-7419-1) vim_9.1.0496-1ubuntu6.5_amd64.debLinux
Vi IMproved - enhanced vi editor (USN-7419-1) vim_9.1.0496-1ubuntu6.5_i386.debLinux
vim Security Update (ALAS-2025-932) xxd-9.1.1202-1.amzn2023.0.1.x86_64.rpmLinux
vim Security Update (ALAS-2025-932) vim-minimal-9.1.1202-1.amzn2023.0.1.x86_64.rpmLinux
vim Security Update (ALAS-2025-932) vim-filesystem-9.1.1202-1.amzn2023.0.1.noarch.rpmLinux
vim Security Update (ALAS-2025-932) vim-enhanced-9.1.1202-1.amzn2023.0.1.x86_64.rpmLinux
vim Security Update (ALAS-2025-932) vim-default-editor-9.1.1202-1.amzn2023.0.1.noarch.rpmLinux
vim Security Update (ALAS-2025-932) vim-data-9.1.1202-1.amzn2023.0.1.noarch.rpmLinux
vim Security Update (ALAS-2025-932) vim-common-9.1.1202-1.amzn2023.0.1.x86_64.rpmLinux
vim Security Update (ALAS-2025-2827) xxd-9.0.2153-1.amzn2.0.4.x86_64.rpmLinux
vim Security Update (ALAS-2025-2827) vim-minimal-9.0.2153-1.amzn2.0.4.x86_64.rpmLinux
vim Security Update (ALAS-2025-2827) vim-filesystem-9.0.2153-1.amzn2.0.4.noarch.rpmLinux
vim Security Update (ALAS-2025-2827) vim-enhanced-9.0.2153-1.amzn2.0.4.x86_64.rpmLinux
vim Security Update (ALAS-2025-2827) vim-data-9.0.2153-1.amzn2.0.4.noarch.rpmLinux
vim Security Update (ALAS-2025-2827) vim-common-9.0.2153-1.amzn2.0.4.x86_64.rpmLinux
vim Security Update (ALAS-2025-2827) vim-X11-9.0.2153-1.amzn2.0.4.x86_64.rpmLinux
vim Security Update (ALAS2023-2025-932) vim-common-9.1.1202-1.amzn2023.0.1.x86_64.rpmLinux
vim Security Update (ALAS2023-2025-932) vim-data-9.1.1202-1.amzn2023.0.1.noarch.rpmLinux
vim Security Update (ALAS2023-2025-932) vim-default-editor-9.1.1202-1.amzn2023.0.1.noarch.rpmLinux
vim Security Update (ALAS2023-2025-932) vim-enhanced-9.1.1202-1.amzn2023.0.1.x86_64.rpmLinux
vim Security Update (ALAS2023-2025-932) vim-filesystem-9.1.1202-1.amzn2023.0.1.noarch.rpmLinux
vim Security Update (ALAS2023-2025-932) vim-minimal-9.1.1202-1.amzn2023.0.1.x86_64.rpmLinux
vim Security Update (ALAS2023-2025-932) xxd-9.1.1202-1.amzn2023.0.1.x86_64.rpmLinux
vim Security Update (ALAS2-2025-2827) vim-X11-9.0.2153-1.amzn2.0.4.x86_64.rpmLinux
vim Security Update (ALAS2-2025-2827) vim-common-9.0.2153-1.amzn2.0.4.x86_64.rpmLinux
vim Security Update (ALAS2-2025-2827) vim-data-9.0.2153-1.amzn2.0.4.noarch.rpmLinux
vim Security Update (ALAS2-2025-2827) vim-enhanced-9.0.2153-1.amzn2.0.4.x86_64.rpmLinux
vim Security Update (ALAS2-2025-2827) vim-filesystem-9.0.2153-1.amzn2.0.4.noarch.rpmLinux
vim Security Update (ALAS2-2025-2827) vim-minimal-9.0.2153-1.amzn2.0.4.x86_64.rpmLinux
vim Security Update (ALAS2-2025-2827) xxd-9.0.2153-1.amzn2.0.4.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234