An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.
Product | Vendor | Version |
---|---|---|
n/a | n/a | < b446631f355ece73b13c311dd712c47381a23172 |