PT-2023-8858 · Vim+6 · Vim+6

Fabian Toepfer

·

Published

2023-11-16

·

Updated

2026-03-29

·

CVE-2023-48236

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.0.2111
Description The issue is related to the use of the z= command in Vim, which can cause an overflow of the count with values larger than MAX INT. This can lead to a crash, but the impact is low and user interaction is required. The vulnerability can be exploited by an attacker to cause a denial of service.
Recommendations For versions prior to 9.0.2111, upgrade to release version 9.0.2111 or later, as this version includes the commit 73b2d379 that addresses the vulnerability. There are no known workarounds for this issue.

Exploit

Fix

DoS

Integer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2023-7676
ALT-PU-2023-7776
ALT-PU-2023-7778
ALT-PU-2024-1095
AZL-32012
BDU:2024-02417
CVE-2023-48236
ECHO-193B-A5B8-9492
GHSA-PR4C-932V-8HX5
MGASA-2023-0341
OESA-2023-1874
OESA-2023-1876
OESA-2023-1883
OESA-2023-1884
OESA-2023-1885
OPENSUSE-SU-2024_1287-1
SUSE-SU-2024:0783-1
SUSE-SU-2024:0871-1
SUSE-SU-2024:1287-1
USN-6557-1

Affected Products

Alt Linux
Debian
Linuxmint
Red Os
Suse
Ubuntu
Vim