Bug 1126750 (CVE-2018-20786) - VUL-1: CVE-2018-20786: vim: libvterm mishandles certain out-of-memory conditions, leading to a denial of service
Summary: VUL-1: CVE-2018-20786: vim: libvterm mishandles certain out-of-memory conditi...
Status: RESOLVED WONTFIX
Alias: CVE-2018-20786
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Assignee: Ismail Dönmez
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/225335/
Whiteboard: CVSSv3:SUSE:CVE-2018-20786:3.3:(AV:L/...
Keywords:
Depends on:
Blocks:
 
Reported: 2019-02-25 09:19 UTC by Robert Frohl
Modified: 2024-05-24 10:21 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Frohl 2019-02-25 09:19:30 UTC
CVE-2018-20786

libvterm through 0+bzr726, as used in Vim and other products, mishandles certain
out-of-memory conditions, leading to a denial of service (application crash),
related to screen.c, state.c, and vterm.c.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-20786
https://github.com/vim/vim/issues/3711
https://github.com/vim/vim/commit/cd929f7ba8cc5b6d6dcf35c8b34124e969fed6b8
Comment 1 Robert Frohl 2019-02-25 09:20:54 UTC
Only treating SUSE:SLE-15:Update as affected. In previous version of vim libvterm was not included.
Comment 4 Alexander Bergmann 2024-05-24 10:21:38 UTC
Minor issue. Won't fix for SUSE:SLE-15:Update.

Closing bug.