Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2023-48231
HistoryNov 16, 2023 - 11:15 p.m.

CVE-2023-48231

2023-11-1623:15:08
Alpine Linux Development Team
security.alpinelinux.org
16
cve-2023-48231
vulnerability
window access
exploitation
commit 25aabc2b
upgrade
unix

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

AI Score

7.4

Confidence

Low

EPSS

0.001

Percentile

31.0%

Vim is an open source command line text editor. When closing a window, vim may try to access already freed window structure. Exploitation beyond crashing the application has not been shown to be viable. This issue has been addressed in commit 25aabc2b which has been included in release version 9.0.2106. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

AI Score

7.4

Confidence

Low

EPSS

0.001

Percentile

31.0%