CVE-2023-5344

vim: Heap-based Buffer Overflow (CVE-2023-5344)

Description

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.

Source: NVDCVELISTV5

Metrics

Severity
high
no public PoC known
7.5
Source: nvd-v3
66.1 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
1.2 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2023-10-02 19:20 UTC
CWE-122

Weakness classes (CWE)

  • CWE-122Variant

    Heap-based Buffer Overflow

    A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

    cwe.mitre.org →

Affected operating systems

  • other

    fedoraproject / fedora37

  • other

    fedoraproject / fedora38

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • vim

    vim9.0.1969

References & sources

IDCVE-2023-5344