Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-0054

Опубликовано: 03 янв. 2023
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145.

An out-of-bounds write flaw was found in Vim, in the do_string_sub function in the eval.c file. The issue occurs because of an invalid memory access due to a missing check of the return value of the vim_regsub function when a specially crafted input is processed. This flaw allows an attacker who can trick a user into opening a specially crafted file to trigger the out-of-bounds write, causing the application to crash.

Отчет

Red Hat Product Security has rated this issue as having a Low security impact because the user has to run an untrusted file in script mode. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/ and Red Hat Enterprise Linux Life Cycle & Updates Policy: https://access.redhat.com/support/policy/updates/errata/.

Меры по смягчению последствий

Do not run untrusted vim scripts as it is not recommended.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6vimOut of support scope
Red Hat Enterprise Linux 7vimOut of support scope
Red Hat Enterprise Linux 8vimFix deferred
Red Hat Enterprise Linux 9vimFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-252->CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2161349vim: out-of-bounds write in do_string_sub() in eval.c

EPSS

Процентиль: 2%
0.00016
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 2 лет назад

Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145.

CVSS3: 7.8
nvd
больше 2 лет назад

Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145.

CVSS3: 7.8
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 7.8
debian
больше 2 лет назад

Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145.

CVSS3: 7.8
github
больше 2 лет назад

Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145.

EPSS

Процентиль: 2%
0.00016
Низкий

7.8 High

CVSS3