CVE-2023-48237

Name
CVE-2023-48237
Description
Vim is an open source command line text editor. In affected versions when shifting lines in operator pending mode and using a very large value, it may be possible to overflow the size of integer. Impact is low, user interaction is required and a crash may not even happen in all situations. This issue has been addressed in commit `6bf131888` which has been included in version 9.0.2112. Users are advised to upgrade. There are no known workarounds for this vulnerability.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
https://github.com/vim/vim/security/advisories/GHSA-f2m2-v387-gv87
https://github.com/vim/vim/commit/6bf131888a3d1de62bbfa8a7ea03c0ddccfd496e
http://www.openwall.com/lists/oss-security/2023/11/16/1
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M3VQF7CL3V6FGSEW37WNDFBRRILR65AK/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VNRNYLWXZOGTYWE5HMFNQ5FVE3HBUHF6/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4UJAK2W5S7G75ETDAEM3BDUCVSXCEGRD/
security-advisories@github.com https://security.netapp.com/advisory/ntap-20231227-0005/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:* vim >= None < 9.0.2112

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
vim 3.18-main 9.0.2073-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
vim 3.17-main 9.0.0999-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
vim 3.15-main 8.2.4836-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
vim 3.16-main 8.2.5000-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable