CVE-2023-5344
vim: Heap-based Buffer Overflow (CVE-2023-5344)
highEPSS 1.2%
Description
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.
Metrics
Severity
high
63.43
no public PoC known
4.0
Published
2023-10-02 19:20 UTC
CWE-122
Weakness classes (CWE)
CWE-122Variant
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
cwe.mitre.org →
Affected operating systems
other
fedoraproject / fedora37
other
fedoraproject / fedora38
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
vim
vim9.0.1969
References & sources
- https://huntr.dev/bounties/530cb762-899e-48d7-b50e-dad09eb775bf
- https://github.com/vim/vim/commit/3bd7fa12e146c6051490d048a4acbfba974eeb04
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4W665GQBN6S6ZDMYWVF4X7KMFI7AQKJL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZOXBUJLJ5VSPN3YXWN7XZA4JDYKNE7GZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XPT7NMYJRLBPIALGSE24UWTY6F774GZW/
- https://support.apple.com/kb/HT214038
- https://support.apple.com/kb/HT214036
- https://support.apple.com/kb/HT214037
- http://seclists.org/fulldisclosure/2023/Dec/9
- http://seclists.org/fulldisclosure/2023/Dec/10
- http://seclists.org/fulldisclosure/2023/Dec/11
- https://lists.debian.org/debian-lts-announce/2025/03/msg00023.html
IDCVE-2023-5344