Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Mageia 9 MGASA-2023-0341 moderate: vim access crash exploit

mageia
Calendar Grey December 8, 2023
Dist Mageia Esm H88
Recent updates to vim packages fix bugs in Mageia, improving security and addressing potential system crashes.
The updated packages fix security vulnerabilities When closing a window, vim may try to access already freed window structure

Summary

The updated packages fix security vulnerabilities
When closing a window, vim may try to access already freed window structure. Exploitation beyond crashing the application has not been shown to be viable. (CVE-2023-48231)
A floating point exception may occur when calculating the line offset for overlong lines and smooth scrolling is enabled and the cpo-settings include the 'n' flag. This may happen when a window border is present and when the wrapped line continues on the next physical line directly in the window border because the 'cpo' setting includes the 'n' flag. Only users with non-default settings are affected and the exception should only result in a crash. (CVE-2023-48232)
If the count after the :s command is larger than what fits into a (signed) long variable, abort with e_value_too_large. Impact is low, user interaction is required and a crash may not even happen in all situations. (CVE-2023-48233)
When getting the count for a normal mode z command, it may overflow for la...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=32546

- https://www.openwall.com/lists/oss-security/2023/11/16/1

- https://www.openwall.com/lists/oss-security/2023/11/22/3

- https://www.cve.org/CVERecord?id=CVE-2023-48231

- https://www.cve.org/CVERecord?id=CVE-2023-48232

- https://www.cve.org/CVERecord?id=CVE-2023-48233

- https://www.cve.org/CVERecord?id=CVE-2023-48234

- https://www.cve.org/CVERecord?id=CVE-2023-48235

- https://www.cve.org/CVERecord?id=CVE-2023-48236

- https://www.cve.org/CVERecord?id=CVE-2023-48237

- https://www.cve.org/CVERecord?id=CVE-2023-48706

Resolution

SRPMS

- 9/core/vim-9.0.2130-2.mga9

Publication date: 08 Dec 2023
URL: https://advisories.mageia.org/MGASA-2023-0341.html
Type: security
CVE: CVE-2023-48231, CVE-2023-48232, CVE-2023-48233, CVE-2023-48234, CVE-2023-48235, CVE-2023-48236, CVE-2023-48237, CVE-2023-48706

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here