PT-2023-8859 · Vim+6 · Vim+6

Fabian Toepfer

·

Publicado

2023-11-16

·

Atualizado

2026-03-29

·

CVE-2023-48237

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.0.2112
Description The issue is related to the use of very large values when shifting lines in operator pending mode, potentially leading to an integer overflow. This may cause a crash, although the impact is considered low and user interaction is required. There are no known workarounds for this issue.
Recommendations For versions prior to 9.0.2112, upgrade to version 9.0.2112 or later to resolve the issue. As a temporary workaround, consider avoiding the use of very large values when shifting lines in operator pending mode until a patch is applied.

Exploit

Correção

DoS

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-7676
ALT-PU-2023-7776
ALT-PU-2023-7778
ALT-PU-2024-1095
AZL-32011
BDU:2024-02418
CVE-2023-48237
ECHO-681D-921D-2DE3
GHSA-F2M2-V387-GV87
MGASA-2023-0341
OESA-2023-1874
OESA-2023-1876
OESA-2023-1883
OESA-2023-1884
OESA-2023-1885
OPENSUSE-SU-2024_1287-1
SUSE-SU-2024:0783-1
SUSE-SU-2024:0871-1
SUSE-SU-2024:1287-1
USN-6557-1

Produtos afetados

Alt Linux
Debian
Linuxmint
Red Os
Suse
Ubuntu
Vim