Google: app-editors/vim, app-editors/vim-core: security update to 18613.75.4

medium Tenable Self-Hosted Container Security Plugin ID 471686

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Vim is an open source command line text editor. When performing a search and displaying the search-count
message is disabled (:set shm+=S), the search pattern is displayed at the bottom of the screen in a buffer
(msgbuf). When right-left mode (:set rl) is enabled, the search pattern is reversed. This happens by
allocating a new buffer. If the search pattern contains some ASCII NUL characters, the buffer allocated
will be smaller than the original allocated buffer (because for allocating the reversed buffer, the
strlen() function is called, which only counts until it notices an ASCII NUL byte ) and thus the original
length indicator is wrong. This causes an overflow when accessing characters inside the msgbuf by the
previously (now wrong) length of the msgbuf. The issue has been fixed as of Vim patch v9.1.0689.
(CVE-2024-43790)

Solution

Update the app-editors/vim library and its related packages to version 18613.75.4 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 471686

Version: Revision 1.3

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-43790

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/22/2024

Reference Information

CVE: CVE-2024-43790