5.3

CVE-2023-2426

Exploit

Use of Out-of-range Pointer Offset in vim/vim

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version 37
Fedoraproject ≫ Fedora Version 38
Apple ≫ macOS Version 11.7.9
Apple ≫ macOS Version 12.6.8
Neovim ≫ Neovim Version >= 0.7.0 < 0.10.0
Vim ≫ Vim Version < 9.0.1499
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.41% 0.325
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 1.8 3.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
security@huntr.dev 6.8 2.5 3.7
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
CWE-823 Use of Out-of-range Pointer Offset

The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.

https://github.com/vim/vim/commit/caf642c25de526229264cab9425e7c9979f3509b
Patch
https://huntr.dev/bounties/3451be4c-91c8-4d08-926b-cbff7396f425
Exploit
https://support.apple.com/kb/HT213844
Third Party Advisory
https://support.apple.com/kb/HT213845
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LOJP6M7ZTKZQYOGVOOAY6TIE6ACBJL55/
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PCLJN4QINITA3ZASKLEJ64C5TFNKELMO/
Third Party Advisory
Mailing List