PT-2023-8858 · Vim+6 · Vim+6
Fabian Toepfer
·
Published
2023-11-16
·
Updated
2026-03-29
·
CVE-2023-48236
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Vim versions prior to 9.0.2111
Description
The issue is related to the use of the z= command in Vim, which can cause an overflow of the count with values larger than MAX INT. This can lead to a crash, but the impact is low and user interaction is required. The vulnerability can be exploited by an attacker to cause a denial of service.
Recommendations
For versions prior to 9.0.2111, upgrade to release version 9.0.2111 or later, as this version includes the commit
73b2d379 that addresses the vulnerability. There are no known workarounds for this issue.Exploit
Fix
DoS
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Linuxmint
Red Os
Suse
Ubuntu
Vim