CVE-2023-2426
Publication date 29 April 2023
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499.
Status
Package | Ubuntu Release | Status |
---|---|---|
vim | ||
22.04 LTS jammy |
Fixed 2:8.2.3995-1ubuntu2.8
|
|
20.04 LTS focal |
Not affected
|
|
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
Notes
rodrigo-zaiden
issue was likely introduced around versions 8.2.1665 (commit 635414dd) and 8.2.2813 (commit bb01a1ef), that is, affects Ubuntu versions starting from jammy. PoC easily reproduces on affected versions.
Severity score breakdown
Parameter | Value |
---|---|
Base score | 5.5 · Medium |
Attack vector | Local |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-6154-1
- Vim vulnerabilities
- 12 June 2023