Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with Vim and then press 'x' on such a strange filename. The issue has been fixed as of Vim patch v9.1.1198.
History

Fri, 14 Mar 2025 14:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 13 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Description Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with Vim and then press 'x' on such a strange filename. The issue has been fixed as of Vim patch v9.1.1198.
Title Vim vulnerable to potential data loss with zip.vim and special crafted zip files
Weaknesses CWE-88
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-03-13T17:04:56.920Z

Updated: 2025-03-13T18:39:40.959Z

Reserved: 2025-03-11T14:23:00.474Z

Link: CVE-2025-29768

cve-icon Vulnrichment

Updated: 2025-03-13T18:39:37.470Z

cve-icon NVD

Status : Received

Published: 2025-03-13T17:15:37.623

Modified: 2025-03-13T17:15:37.623

Link: CVE-2025-29768

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-03-13T17:04:56Z

Links: CVE-2025-29768 - Bugzilla