USN-6154-1
Dashboard / Vulnerabilities / USN-6154-1
USN-6154-1
Summary: vim vulnerabilities
Details: It was discovered that Vim was using uninitialized memory when fuzzy matching, which could lead to invalid memory access. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS, Ubuntu 22.10 and Ubuntu 23.04. (CVE-2023-2426) It was discovered that Vim was not properly performing bounds checks when processing register contents, which could lead to a NULL pointer dereference. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2023-2609) It was discovered that Vim was not properly limiting the length of substitution expression strings, which could lead to excessive memory consumption. An attacker could possibly use this issue to cause a denial of service. (CVE-2023-2610)
References: https://ubuntu.com/security/notices/USN-6154-1, https://ubuntu.com/security/CVE-2023-2426, https://ubuntu.com/security/CVE-2023-2609, https://ubuntu.com/security/CVE-2023-2610
Affected packages
Package
Name: vim
Purl: pkg:deb/ubuntu/vim?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
