Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-41957

Опубликовано: 01 авг. 2024
Источник: nvd
CVSS3: 4.5
CVSS3: 5.3
EPSS Низкий

Описание

Vim is an open source command line text editor. Vim < v9.1.0647 has double free in src/alloc.c:616. When closing a window, the corresponding tagstack data will be cleared and freed. However a bit later, the quickfix list belonging to that window will also be cleared and if that quickfix list points to the same tagstack data, Vim will try to free it again, resulting in a double-free/use-after-free access exception. Impact is low since the user must intentionally execute vim with several non-default flags, but it may cause a crash of Vim. The issue has been fixed as of Vim patch v9.1.0647

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*
Версия до 9.1.0647 (исключая)

EPSS

Процентиль: 28%
0.001
Низкий

4.5 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-415
CWE-415

Связанные уязвимости

CVSS3: 4.5
ubuntu
больше 1 года назад

Vim is an open source command line text editor. Vim < v9.1.0647 has double free in src/alloc.c:616. When closing a window, the corresponding tagstack data will be cleared and freed. However a bit later, the quickfix list belonging to that window will also be cleared and if that quickfix list points to the same tagstack data, Vim will try to free it again, resulting in a double-free/use-after-free access exception. Impact is low since the user must intentionally execute vim with several non-default flags, but it may cause a crash of Vim. The issue has been fixed as of Vim patch v9.1.0647

CVSS3: 4.5
redhat
больше 1 года назад

Vim is an open source command line text editor. Vim < v9.1.0647 has double free in src/alloc.c:616. When closing a window, the corresponding tagstack data will be cleared and freed. However a bit later, the quickfix list belonging to that window will also be cleared and if that quickfix list points to the same tagstack data, Vim will try to free it again, resulting in a double-free/use-after-free access exception. Impact is low since the user must intentionally execute vim with several non-default flags, but it may cause a crash of Vim. The issue has been fixed as of Vim patch v9.1.0647

CVSS3: 5.3
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 4.5
debian
больше 1 года назад

Vim is an open source command line text editor. Vim < v9.1.0647 has do ...

CVSS3: 4.5
fstec
больше 1 года назад

Уязвимость функции tagstack_clear_entry() файла src/alloc.c текстового редактора vim, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 28%
0.001
Низкий

4.5 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-415
CWE-415