Synopsis
The remote Amazon Linux 2 host is missing a security update.
Description
It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2-2025-2827 advisory.
    A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects     unknown code of the file src/main.c. The manipulation of the argument --log leads to memory corruption. It     is possible to launch the attack on the local host. Upgrading to version 9.1.1097 is able to address this     issue. The patch is identified as c5654b84480822817bb7b69ebc97c174c91185e9. It is recommended to upgrade     the affected component. (CVE-2025-1215)
    Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages     using the `:redir` ex command to register, variables and files. It also allows to show the contents of     registers using the `:registers` or `:display` ex command. When redirecting the output of `:display` to a     register, Vim will free the register content before storing the new content in the register. Now when     redirecting the `:display` command to a register that is being displayed, Vim will free the content while     shortly afterwards trying to access it, which leads to a use-after-free. Vim pre 9.1.1115 checks in the     ex_display() function, that it does not try to redirect to a register while displaying this register at     the same time. However this check is not complete, and so Vim does not check the `+` and `*` registers     (which typically donate the X11/clipboard registers, and when a clipboard connection is not possible will     fall back to use register 0 instead. In Patch 9.1.1115 Vim will therefore skip outputting to register zero     when trying to redirect to the clipboard registers `*` or `+`. Users are advised to upgrade. There are no     known workarounds for this vulnerability. (CVE-2025-26603)
    Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in     versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with     Vim and then press 'x' on such a strange filename. The issue has been fixed as of Vim patch v9.1.1198.
    (CVE-2025-29768)
Tenable has extracted the preceding description block directly from the tested product security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Run 'yum update vim' to update your system.
Plugin Details
File Name: al2_ALAS-2025-2827.nasl
Agent: unix
Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus
Risk Information
Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:P
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Threat Vector: CVSS:4.0/E:U
Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Vulnerability Information
CPE: cpe:/o:amazon:linux:2, p-cpe:/a:amazon:linux:xxd, p-cpe:/a:amazon:linux:vim-x11, p-cpe:/a:amazon:linux:vim-common, p-cpe:/a:amazon:linux:vim-debuginfo, p-cpe:/a:amazon:linux:vim-enhanced, p-cpe:/a:amazon:linux:vim-filesystem, p-cpe:/a:amazon:linux:vim-minimal, p-cpe:/a:amazon:linux:vim-data
Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list
Exploit Ease: No known exploits are available
Patch Publication Date: 4/9/2025
Vulnerability Publication Date: 2/12/2025