Lucene search

K
cvelistGitHub_MCVELIST:CVE-2023-48231
HistoryNov 16, 2023 - 10:59 p.m.

CVE-2023-48231 Use-After-Free in win_close() in vim

2023-11-1622:59:37
CWE-416
GitHub_M
www.cve.org
7
cve-2023-48231
open source
text editor
exploitation
window structure
commit 25aabc2b
release version 9.0.2106
upgrade
vulnerability

CVSS3

3.9

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

31.0%

Vim is an open source command line text editor. When closing a window, vim may try to access already freed window structure. Exploitation beyond crashing the application has not been shown to be viable. This issue has been addressed in commit 25aabc2b which has been included in release version 9.0.2106. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CNA Affected

[
  {
    "vendor": "vim",
    "product": "vim",
    "versions": [
      {
        "version": "< 9.0.2106",
        "status": "affected"
      }
    ]
  }
]

CVSS3

3.9

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

31.0%