PT-2023-8852 · Vim+6 · Vim+6

Published

2023-10-11

·

Updated

2024-03-29

·

CVE-2023-5535

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vim versions prior to 9.0.2010
Description The issue is related to a Use After Free vulnerability in the buf contents changed() function of the vim text editor, which is associated with the use of memory after it has been freed. Exploitation of this issue may allow an attacker to cause a denial of service.
Recommendations For versions prior to 9.0.2010, update to version 9.0.2010 or later to resolve the issue. As a temporary workaround, consider disabling the buf contents changed() function until a patch is available.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2023-6840
ALT-PU-2023-7025
ALT-PU-2023-7047
ALT-PU-2023-7253
AZL-31499
BDU:2024-02411
CVE-2023-5535
ECHO-61BE-0CF4-6A99
MGASA-2023-0305
OESA-2023-1749
OPENSUSE-SU-2023_4557-1
OPENSUSE-SU-2023_4587-1
SUSE-SU-2023:4557-1
SUSE-SU-2023:4560-1
SUSE-SU-2023:4587-1
USN-6452-1

Affected Products

Alt Linux
Debian
Linuxmint
Red Os
Suse
Ubuntu
Vim