7.5
CVSSv3

CVE-2023-5344

Published: 02/10/2023 Updated: 13/12/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Heap-based Buffer Overflow in GitHub repository vim/vim before 9.0.1969.

Vulnerable Product Search on Vulmon Subscribe to Product

vim vim

fedoraproject fedora 37

fedoraproject fedora 38

Vendor Advisories

Debian Bug report logs - #1053694 vim: CVE-2023-5344 Package: src:vim; Maintainer for src:vim is Debian Vim Maintainers <team+vim@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 8 Oct 2023 20:51:01 UTC Severity: important Tags: security, upstream Found in version vim/2:901894 ...
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 901969 (CVE-2023-5344) ...
Vim is an improved version of the good old UNIX editor Vi Heap-use-after-free in memory allocated in the function `ga_grow_inner` in in the file `src/allocc` at line 748, which is freed in the file `src/ex_docmdc` in the function `do_cmdline` at line 1010 and then used again in `src/cmdhistc` at line 759 When using the `:history` command, it's ...
Description<!---->A heap-based buffer overflow vulnerability was found in Vim's trunc_string() function of the src/messagec file This flaw allows an attacker to trick a user into opening a specially crafted file, triggering a heap-based buffer overflow that causes an application to crash, leading to a denial of serviceA heap-based buffer overflo ...
About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the&nbsp;Apple security releases page Apple security documents reference vulnerabilities by&nbsp;CVE-ID&nbsp;whe ...
About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the&nbsp;Apple security releases page Apple security documents reference vulnerabilities by&nbsp;CVE-ID&nbsp;whe ...
About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the&nbsp;Apple security releases page Apple security documents reference vulnerabilities by&nbsp;CVE-ID&nbsp;whe ...