Lucene search

K
mageiaGentoo FoundationMGASA-2023-0269
HistorySep 27, 2023 - 7:31 p.m.

Updated vim packages fix security vulnerability

2023-09-2719:31:30
Gentoo Foundation
advisories.mageia.org
39
vim
github
security vulnerability
use after free
cve-2023-4752
unix

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

23.6%

Use After Free in GitHub repository vim/vim prior to 9.0.1840. (CVE-2023-4733) Use After Free in GitHub repository vim/vim prior to 9.0.1857. (CVE-2023-4750) Use After Free in GitHub repository vim/vim prior to 9.0.1858. (CVE-2023-4752)

OSVersionArchitecturePackageVersionFilename
Mageia8noarchvim< 9.0.1882-1vim-9.0.1882-1.mga8
Mageia9noarchvim< 9.0.1882-1vim-9.0.1882-1.mga9

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

23.6%