Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-48231
HistoryNov 16, 2023 - 12:00 a.m.

CVE-2023-48231

2023-11-1600:00:00
ubuntu.com
ubuntu.com
9
vim
open source
text editor
window
structure
exploitation
application
commit
release
upgrade
vulnerability
unix

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

AI Score

7

Confidence

High

EPSS

0.001

Percentile

31.0%

Vim is an open source command line text editor. When closing a window, vim
may try to access already freed window structure. Exploitation beyond
crashing the application has not been shown to be viable. This issue has
been addressed in commit 25aabc2b which has been included in release
version 9.0.2106. Users are advised to upgrade. There are no known
workarounds for this vulnerability.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchvim< 2:8.0.1453-1ubuntu1.13+esm7UNKNOWN
ubuntu20.04noarchvim< 2:8.1.2269-1ubuntu5.21UNKNOWN
ubuntu22.04noarchvim< 2:8.2.3995-1ubuntu2.15UNKNOWN
ubuntu23.04noarchvim< 2:9.0.1000-4ubuntu3.3UNKNOWN
ubuntu23.10noarchvim< 2:9.0.1672-1ubuntu2.2UNKNOWN
ubuntu14.04noarchvim< 2:7.4.052-1ubuntu3.1+esm15UNKNOWN
ubuntu16.04noarchvim< 2:7.4.1689-3ubuntu1.5+esm22UNKNOWN

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

AI Score

7

Confidence

High

EPSS

0.001

Percentile

31.0%