Google: app-editors/vim, app-editors/vim-core: security update to 18244.291.20

medium Tenable Cloud Security Plugin ID 451439

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Vim is an open source, command line text editor. Patch v9.1.0038 optimized how the cursor position is
calculated and removed a loop, that verified that the cursor position always points inside a line and does
not become invalid by pointing beyond the end of a line. Back then we assumed this loop is unnecessary.
However, this change made it possible that the cursor position stays invalid and points beyond the end of
a line, which would eventually cause a heap-buffer-overflow when trying to access the line pointer at the
specified cursor position. It's not quite clear yet, what can lead to this situation that the cursor
points to an invalid position. That's why patch v9.1.0707 does not include a test case. The only observed
impact has been a program crash. This issue has been addressed in with the patch v9.1.0707. All users are
advised to upgrade. (CVE-2024-45306)

Solution

Update the app-editors/vim library and its related packages to version 18244.291.20 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 451439

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 3.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2024-45306

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/2/2024

Reference Information

CVE: CVE-2024-45306