PT-2023-1227 · Vim+8 · Vim+8

Brammool

·

Published

2023-01-21

·

Updated

2023-10-22

·

CVE-2023-0433

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.0.1225
Description The issue is related to a heap-based buffer overflow in the Vim text editor, specifically affecting functions such as same leader() and utfc ptr2len(). This can allow an attacker to execute arbitrary code on the target system.
Recommendations For versions prior to 9.0.1225, update to version 9.0.1225 or later to resolve the issue. As a temporary workaround, consider restricting the use of the affected functions same leader() and utfc ptr2len() until a patch is applied.

Exploit

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1125
ALT-PU-2023-1170
ALT-PU-2023-1184
AZL-13126
BDU:2023-00451
CVE-2023-0433
MGASA-2023-0075
OESA-2023-1066
OPENSUSE-SU-2023_0211-1
ROSA-SA-2023-2268
SUSE-SU-2023:0209-1
SUSE-SU-2023:0211-1
USN-5836-1
USN-5963-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Apple Macos
Red Os
Suse
Ubuntu
Vim