Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-4752

Опубликовано: 04 сент. 2023
Источник: redhat
CVSS3: 7

Описание

Use After Free in GitHub repository vim/vim prior to 9.0.1858.

A flaw was found in Vim, where it is vulnerable to a use-after-free in the ins_compl_get_exp function. This flaw allows a specially crafted file to crash software, use unexpected values, or possibly execute code when opened in Vim.

Отчет

Red Hat Product Security has rated this issue as having a Low security impact, because the "victim" has to run an untrusted file IN SCRIPT MODE. Someone who is running untrusted files in script mode is equivalent to someone just taking a random python script and running it.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8vimWill not fix
Red Hat Enterprise Linux 9vimFixedRHSA-2025:744013.05.2025
Red Hat Enterprise Linux 9vimFixedRHSA-2025:744013.05.2025
Red Hat Discovery 1.14registry.redhat.io/discovery/discovery-ui-rhel9FixedRHSA-2025:838502.06.2025

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2237311vim: use-after-free in function ins_compl_get_exp in vim/vim

7 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 2 года назад

Use After Free in GitHub repository vim/vim prior to 9.0.1858.

CVSS3: 7.8
nvd
почти 2 года назад

Use After Free in GitHub repository vim/vim prior to 9.0.1858.

CVSS3: 7.8
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 7.8
debian
почти 2 года назад

Use After Free in GitHub repository vim/vim prior to 9.0.1858.

CVSS3: 7.8
github
почти 2 года назад

Use After Free in GitHub repository vim/vim prior to 9.0.1858.

7 High

CVSS3