ALT-PU-2023-2168-1
Package vim updated to version 9.0.1174-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
Published: 2023-01-05
BDU:2023-00068
Уязвимость функции build_stl_str_hl() (buffer.c) текстового редактора Vim, позволяющая нарушителю выполнить произвольный код
Severity: HIGH (7.8)
Vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity: HIGH (7.2)
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
References:
Published: 2023-01-05
BDU:2023-00069
Уязвимость функции msg_puts_printf() (message.c) текстового редактора Vim, позволяющая нарушителю выполнить произвольный код в целевой системе
Severity: HIGH (7.8)
Vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity: HIGH (7.2)
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
References:
Published: 2023-01-05
BDU:2023-00070
Уязвимость функции do_string_sub() (eval.c) текстового редактора Vim, позволяющая нарушителю выполнить произвольный код
Severity: HIGH (7.8)
Vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity: HIGH (7.2)
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
References:
Published: 2023-01-04
Modified: 2025-01-17
Modified: 2025-01-17
CVE-2023-0049
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.
Severity: HIGH (7.8)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
- http://seclists.org/fulldisclosure/2023/Mar/17
- https://github.com/vim/vim/commit/7b17eb4b063a234376c1ec909ee293e42cff290c
- https://huntr.dev/bounties/5e6f325c-ba54-4bf0-b050-dca048fd3fd9
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3Y752EAVACVC5XY2TMGGOAIU25VQRPDW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T33LLWHLH63XDCO5OME7NWN63RA4U5HF/
- https://security.gentoo.org/glsa/202305-16
- https://support.apple.com/kb/HT213670
- http://seclists.org/fulldisclosure/2023/Mar/17
- https://github.com/vim/vim/commit/7b17eb4b063a234376c1ec909ee293e42cff290c
- https://huntr.dev/bounties/5e6f325c-ba54-4bf0-b050-dca048fd3fd9
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3Y752EAVACVC5XY2TMGGOAIU25VQRPDW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T33LLWHLH63XDCO5OME7NWN63RA4U5HF/
- https://security.gentoo.org/glsa/202305-16
- https://security.netapp.com/advisory/ntap-20250117-0005/
- https://support.apple.com/kb/HT213670
Published: 2023-01-04
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2023-0051
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1144.
Severity: HIGH (7.8)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
- http://seclists.org/fulldisclosure/2023/Mar/17
- https://github.com/vim/vim/commit/c32949b0779106ed5710ae3bffc5053e49083ab4
- https://huntr.dev/bounties/1c8686db-baa6-42dc-ba45-aed322802de9
- https://security.gentoo.org/glsa/202305-16
- https://support.apple.com/kb/HT213670
- http://seclists.org/fulldisclosure/2023/Mar/17
- https://github.com/vim/vim/commit/c32949b0779106ed5710ae3bffc5053e49083ab4
- https://huntr.dev/bounties/1c8686db-baa6-42dc-ba45-aed322802de9
- https://security.gentoo.org/glsa/202305-16
- https://support.apple.com/kb/HT213670
Published: 2023-01-04
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2023-0054
Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145.
Severity: HIGH (7.8)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
- http://seclists.org/fulldisclosure/2023/Mar/17
- https://github.com/vim/vim/commit/3ac1d97a1d9353490493d30088256360435f7731
- https://huntr.dev/bounties/b289ee0f-fd16-4147-bd01-c6289c45e49d
- https://lists.debian.org/debian-lts-announce/2023/06/msg00015.html
- https://security.gentoo.org/glsa/202305-16
- https://support.apple.com/kb/HT213670
- http://seclists.org/fulldisclosure/2023/Mar/17
- https://github.com/vim/vim/commit/3ac1d97a1d9353490493d30088256360435f7731
- https://huntr.dev/bounties/b289ee0f-fd16-4147-bd01-c6289c45e49d
- https://lists.debian.org/debian-lts-announce/2023/06/msg00015.html
- https://security.gentoo.org/glsa/202305-16
- https://support.apple.com/kb/HT213670