Use After Free in vim/vim
CVE-2023-4733

7.8HIGH

Key Information:

Vendor

Vim

Status
Vendor
CVE Published:
4 September 2023

What is CVE-2023-4733?

The vulnerability arises from a Use After Free condition in the Vim text editor, which can lead to unstable behavior or potential exploitation. The issue affects versions of Vim earlier than 9.0.1840. It is crucial for users to update their installations to enhance security and prevent malicious exploitation. Detailed information regarding this flaw can be found on platforms like GitHub and various security announcements.

Affected Version(s)

vim/vim < 9.0.1840

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.