Use-after-free in Vim - CVE-2020-20703

 

Use-after-free in Vim - CVE-2020-20703

Published: August 31, 2023


Vulnerability identifier: #VU80203
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-20703
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error. A remote attacker can trick the victim to open a specially crafted file and execute arbitrary code on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

Vim
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data

How to mitigate CVE-2020-20703

Install updates from vendor's website.

Vim - update to 8.1.2136
DB2 Warehouse on Cloud Pak for Data - update to 4.8.8
DB2 on Cloud Pak for Data - update to 4.8.8
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.0.1

External References

Related Security Bulletins