Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-4733

Опубликовано: 04 сент. 2023
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

Use After Free in GitHub repository vim/vim prior to 9.0.1840.

A flaw was found in Vim, where it is vulnerable to a use-after-free in the buflist_altfpos function. This flaw allows a specially crafted file to crash software, use unexpected values, or possibly execute code when opened in Vim.

Отчет

Red Hat Product Security has rated this issue as having a Low security impact, because the "victim" has to run an untrusted file IN SCRIPT MODE. Someone who is running untrusted files in script mode is equivalent to someone just taking a random python script and running it.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8vimAffected
Red Hat Enterprise Linux 9vimNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2237315vim: use-after-free in function buflist_altfpos

EPSS

Процентиль: 9%
0.00036
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 2 года назад

Use After Free in GitHub repository vim/vim prior to 9.0.1840.

CVSS3: 7.8
nvd
почти 2 года назад

Use After Free in GitHub repository vim/vim prior to 9.0.1840.

CVSS3: 7.8
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 7.8
debian
почти 2 года назад

Use After Free in GitHub repository vim/vim prior to 9.0.1840.

CVSS3: 7.3
github
почти 2 года назад

Use After Free in GitHub repository vim/vim prior to 9.0.1840.

EPSS

Процентиль: 9%
0.00036
Низкий

7 High

CVSS3