Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-41957

Опубликовано: 01 авг. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 4.5

Описание

Vim is an open source command line text editor. Vim < v9.1.0647 has double free in src/alloc.c:616. When closing a window, the corresponding tagstack data will be cleared and freed. However a bit later, the quickfix list belonging to that window will also be cleared and if that quickfix list points to the same tagstack data, Vim will try to free it again, resulting in a double-free/use-after-free access exception. Impact is low since the user must intentionally execute vim with several non-default flags, but it may cause a crash of Vim. The issue has been fixed as of Vim patch v9.1.0647

РелизСтатусПримечание
devel

released

2:9.1.0496-1ubuntu5
esm-infra-legacy/trusty

not-affected

2:7.4.052-1ubuntu3.1+esm18
esm-infra/bionic

released

2:8.0.1453-1ubuntu1.13+esm9
esm-infra/focal

not-affected

2:8.1.2269-1ubuntu5.24
esm-infra/xenial

released

2:7.4.1689-3ubuntu1.5+esm24
focal

released

2:8.1.2269-1ubuntu5.24
jammy

released

2:8.2.3995-1ubuntu2.18
noble

released

2:9.1.0016-1ubuntu7.2
trusty/esm

released

2:7.4.052-1ubuntu3.1+esm18
upstream

released

9.1.0647

Показывать по

EPSS

Процентиль: 2%
0.00016
Низкий

4.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.5
redhat
11 месяцев назад

Vim is an open source command line text editor. Vim < v9.1.0647 has double free in src/alloc.c:616. When closing a window, the corresponding tagstack data will be cleared and freed. However a bit later, the quickfix list belonging to that window will also be cleared and if that quickfix list points to the same tagstack data, Vim will try to free it again, resulting in a double-free/use-after-free access exception. Impact is low since the user must intentionally execute vim with several non-default flags, but it may cause a crash of Vim. The issue has been fixed as of Vim patch v9.1.0647

CVSS3: 4.5
nvd
11 месяцев назад

Vim is an open source command line text editor. Vim < v9.1.0647 has double free in src/alloc.c:616. When closing a window, the corresponding tagstack data will be cleared and freed. However a bit later, the quickfix list belonging to that window will also be cleared and if that quickfix list points to the same tagstack data, Vim will try to free it again, resulting in a double-free/use-after-free access exception. Impact is low since the user must intentionally execute vim with several non-default flags, but it may cause a crash of Vim. The issue has been fixed as of Vim patch v9.1.0647

CVSS3: 5.3
msrc
10 месяцев назад

Описание отсутствует

CVSS3: 4.5
debian
11 месяцев назад

Vim is an open source command line text editor. Vim < v9.1.0647 has do ...

CVSS3: 4.5
fstec
11 месяцев назад

Уязвимость функции tagstack_clear_entry() файла src/alloc.c текстового редактора vim, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 2%
0.00016
Низкий

4.5 Medium

CVSS3