PT-2023-5102 · Vim+7 · Vim+7

Published

2023-09-04

·

Updated

2024-03-29

·

CVE-2023-4733

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vim versions prior to 9.0.1840
Description The issue is related to a use-after-free problem in the vim text editor, specifically with the buflist altfpos function. This issue is associated with the use of memory after it has been freed. Exploitation of this issue may allow an attacker to execute arbitrary code.
Recommendations For versions prior to 9.0.1840, update to version 9.0.1840 or later to resolve the issue. As a temporary workaround, consider disabling the buflist altfpos function until a patch is available.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2023-5538
ALT-PU-2023-5553
ALT-PU-2023-5877
ALT-PU-2023-5879
AZL-28657
BDU:2023-05668
CVE-2023-4733
ECHO-9657-5463-686D
MGASA-2023-0269
OESA-2023-1653
OPENSUSE-SU-2023_3955-1
OPENSUSE-SU-2023_4557-1
SUSE-SU-2023:3942-1
SUSE-SU-2023:3955-1
SUSE-SU-2023:4557-1
SUSE-SU-2023_3942-1
SUSE-SU-2023_3955-1
USN-6452-1

Affected Products

Alt Linux
Debian
Linuxmint
Apple Macos
Red Os
Suse
Ubuntu
Vim