Integer Overflow or Wraparound in vim/vim
CVE-2023-4734

7.8HIGH

Key Information:

Vendor

Vim

Status
Vendor
CVE Published:
2 September 2023

What is CVE-2023-4734?

An integer overflow or wraparound vulnerability has been identified in the Vim text editor, impacting versions prior to 9.0.1846. This flaw could potentially allow attackers to execute malicious code or cause abnormal application behavior by manipulating integer handling, which may lead to unexpected results. Users of affected versions are advised to update to the latest release to mitigate risks associated with this vulnerability.

Affected Version(s)

vim/vim < 9.0.1846

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.