Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-48236
HistoryNov 16, 2023 - 12:00 a.m.

CVE-2023-48236

2023-11-1600:00:00
ubuntu.com
ubuntu.com
11
vim
overflow
user interaction
low impact
commit
release version
upgrade
workarounds

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

AI Score

4.2

Confidence

High

EPSS

0.001

Percentile

41.8%

Vim is an open source command line text editor. When using the z= command,
the user may overflow the count with values larger than MAX_INT. Impact is
low, user interaction is required and a crash may not even happen in all
situations. This vulnerability has been addressed in commit 73b2d379
which has been included in release version 9.0.2111. Users are advised to
upgrade. There are no known workarounds for this vulnerability.

Notes

Author Note
Priority reason: Requires user interaction
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchvim< 2:8.0.1453-1ubuntu1.13+esm7UNKNOWN
ubuntu20.04noarchvim< 2:8.1.2269-1ubuntu5.21UNKNOWN
ubuntu22.04noarchvim< 2:8.2.3995-1ubuntu2.15UNKNOWN
ubuntu23.04noarchvim< 2:9.0.1000-4ubuntu3.3UNKNOWN
ubuntu23.10noarchvim< 2:9.0.1672-1ubuntu2.2UNKNOWN
ubuntu14.04noarchvim< 2:7.4.052-1ubuntu3.1+esm15UNKNOWN
ubuntu16.04noarchvim< 2:7.4.1689-3ubuntu1.5+esm22UNKNOWN

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

AI Score

4.2

Confidence

High

EPSS

0.001

Percentile

41.8%