Lucene search

K
amazonAmazonALAS2-2023-2319
HistoryOct 30, 2023 - 11:59 p.m.

Low: vim

2023-10-3023:59:00
alas.aws.amazon.com
10
low severity
null pointer dereference
use after free
vim
amazon linux 2
al2 core
yum update

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.1%

Issue Overview:

The severity level was changed from Medium to Low.

NULL Pointer Dereference in GitHub repository vim/vim prior to 20d161ace307e28690229b68584f2d84556f8960. (CVE-2023-5441)

Use After Free in GitHub repository vim/vim prior to v9.0.2010. (CVE-2023-5535)

Affected Packages:

vim

Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.

Issue Correction:
Run yum update vim to update your system.

New Packages:

aarch64:  
    vim-common-9.0.1882-1.amzn2.0.3.aarch64  
    vim-minimal-9.0.1882-1.amzn2.0.3.aarch64  
    vim-enhanced-9.0.1882-1.amzn2.0.3.aarch64  
    vim-X11-9.0.1882-1.amzn2.0.3.aarch64  
    xxd-9.0.1882-1.amzn2.0.3.aarch64  
    vim-debuginfo-9.0.1882-1.amzn2.0.3.aarch64  
  
i686:  
    vim-common-9.0.1882-1.amzn2.0.3.i686  
    vim-minimal-9.0.1882-1.amzn2.0.3.i686  
    vim-enhanced-9.0.1882-1.amzn2.0.3.i686  
    vim-X11-9.0.1882-1.amzn2.0.3.i686  
    xxd-9.0.1882-1.amzn2.0.3.i686  
    vim-debuginfo-9.0.1882-1.amzn2.0.3.i686  
  
noarch:  
    vim-filesystem-9.0.1882-1.amzn2.0.3.noarch  
    vim-data-9.0.1882-1.amzn2.0.3.noarch  
  
src:  
    vim-9.0.1882-1.amzn2.0.3.src  
  
x86_64:  
    vim-common-9.0.1882-1.amzn2.0.3.x86_64  
    vim-minimal-9.0.1882-1.amzn2.0.3.x86_64  
    vim-enhanced-9.0.1882-1.amzn2.0.3.x86_64  
    vim-X11-9.0.1882-1.amzn2.0.3.x86_64  
    xxd-9.0.1882-1.amzn2.0.3.x86_64  
    vim-debuginfo-9.0.1882-1.amzn2.0.3.x86_64  

Additional References

Red Hat: CVE-2023-5441, CVE-2023-5535

Mitre: CVE-2023-5441, CVE-2023-5535

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.1%