PT-2023-1170 · Vim+8 · Vim+8

Brammool

·

Published

2023-01-13

·

Updated

2023-10-22

·

CVE-2023-0288

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.0.1189
Description The issue is related to a heap-based buffer overflow in the Vim text editor, specifically in the src/normal.c component. This overflow occurs in dynamic memory and can be exploited to allow an attacker to execute arbitrary code.
Recommendations For versions prior to 9.0.1189, update to version 9.0.1191 or later to resolve the issue.

Exploit

Fix

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1125
ALT-PU-2023-1170
ALT-PU-2023-1184
AZL-12990
BDU:2023-00387
CVE-2023-0288
OESA-2023-1061
OPENSUSE-SU-2023_0211-1
ROSA-SA-2023-2268
SUSE-SU-2023:0209-1
SUSE-SU-2023:0211-1
USN-5836-1
USN-5963-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Apple Macos
Red Os
Suse
Ubuntu
Vim