ALT-PU-2023-2168-1
Package vim updated to version 9.0.1174-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
Published: 2023-01-05
BDU:2023-00068
Уязвимость функции build_stl_str_hl() (buffer.c) текстового редактора Vim, позволяющая нарушителю выполнить произвольный код
Severity: HIGH (7.8)
Vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
Published: 2023-01-05
BDU:2023-00069
Уязвимость функции msg_puts_printf() (message.c) текстового редактора Vim, позволяющая нарушителю выполнить произвольный код в целевой системе
Severity: HIGH (7.8)
Vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
Published: 2023-01-05
BDU:2023-00070
Уязвимость функции do_string_sub() (eval.c) текстового редактора Vim, позволяющая нарушителю выполнить произвольный код
Severity: HIGH (7.8)
Vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
Published: 2023-01-04
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2023-0049
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.
Severity: HIGH (7.8)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
- 20230327 APPLE-SA-2023-03-27-3 macOS Ventura 13.3
- 20230327 APPLE-SA-2023-03-27-3 macOS Ventura 13.3
- https://github.com/vim/vim/commit/7b17eb4b063a234376c1ec909ee293e42cff290c
- https://github.com/vim/vim/commit/7b17eb4b063a234376c1ec909ee293e42cff290c
- https://huntr.dev/bounties/5e6f325c-ba54-4bf0-b050-dca048fd3fd9
- https://huntr.dev/bounties/5e6f325c-ba54-4bf0-b050-dca048fd3fd9
- FEDORA-2023-0f6a9433cf
- FEDORA-2023-0f6a9433cf
- FEDORA-2023-208f2107d5
- FEDORA-2023-208f2107d5
- GLSA-202305-16
- GLSA-202305-16
- https://support.apple.com/kb/HT213670
- https://support.apple.com/kb/HT213670
Published: 2023-01-04
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2023-0051
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1144.
Severity: HIGH (7.8)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
- 20230327 APPLE-SA-2023-03-27-3 macOS Ventura 13.3
- 20230327 APPLE-SA-2023-03-27-3 macOS Ventura 13.3
- https://github.com/vim/vim/commit/c32949b0779106ed5710ae3bffc5053e49083ab4
- https://github.com/vim/vim/commit/c32949b0779106ed5710ae3bffc5053e49083ab4
- https://huntr.dev/bounties/1c8686db-baa6-42dc-ba45-aed322802de9
- https://huntr.dev/bounties/1c8686db-baa6-42dc-ba45-aed322802de9
- GLSA-202305-16
- GLSA-202305-16
- https://support.apple.com/kb/HT213670
- https://support.apple.com/kb/HT213670
Published: 2023-01-04
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2023-0054
Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145.
Severity: HIGH (7.8)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
- 20230327 APPLE-SA-2023-03-27-3 macOS Ventura 13.3
- 20230327 APPLE-SA-2023-03-27-3 macOS Ventura 13.3
- https://github.com/vim/vim/commit/3ac1d97a1d9353490493d30088256360435f7731
- https://github.com/vim/vim/commit/3ac1d97a1d9353490493d30088256360435f7731
- https://huntr.dev/bounties/b289ee0f-fd16-4147-bd01-c6289c45e49d
- https://huntr.dev/bounties/b289ee0f-fd16-4147-bd01-c6289c45e49d
- [debian-lts-announce] 20230612 [SECURITY] [DLA 3453-1] vim security update
- [debian-lts-announce] 20230612 [SECURITY] [DLA 3453-1] vim security update
- GLSA-202305-16
- GLSA-202305-16
- https://support.apple.com/kb/HT213670
- https://support.apple.com/kb/HT213670