Use-after-free in Vim - CVE-2023-48706
Published: November 22, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error within the ex_substitute() function in src/charset.c when executing the ":s" command. A remote attacker can trick the victim to open a specially crafted file, trigger a use-after-free error and crash the application.
Affected software
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Micro
Ubuntu
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Anolis OS
Fedora
Oracle Solaris
Dell Data Protection Central
PowerProtect DP Series Appliance (IDPA)
PowerStore X
Storage Resource Manager
EMC Cloud Tiering Appliance
vim-gtk (Ubuntu package)
vim-tiny (Ubuntu package)
vim (Ubuntu package)
vim-nox (Ubuntu package)
xxd (Ubuntu package)
vim-gtk3 (Ubuntu package)
vim-athena (Ubuntu package)
vim-common
vim-enhanced
vim-debuginfo
vim-debugsource
vim
vim-X11
vim-filesystem
vim-minimal
vim-data
vim-doc
vim-data-common
gvim-debuginfo
gvim
vim-small
vim-small-debuginfo
Dell EMC Storage Monitoring and Reporting (SMR)
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Dell Secure Connect Gateway
How to mitigate CVE-2023-48706
vim-gtk (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.21, 2:8.2.3995-1ubuntu2.15
vim-tiny (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.21, 2:8.2.3995-1ubuntu2.15, 2:9.0.1000-4ubuntu3.3, 2:9.0.1672-1ubuntu2.2
vim (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.21, 2:8.2.3995-1ubuntu2.15, 2:9.0.1000-4ubuntu3.3, 2:9.0.1672-1ubuntu2.2
vim-nox (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.21, 2:8.2.3995-1ubuntu2.15, 2:9.0.1000-4ubuntu3.3, 2:9.0.1672-1ubuntu2.2
xxd (Ubuntu package) - addressed in versions Ubuntu Pro, 2:8.1.2269-1ubuntu5.21, 2:8.2.3995-1ubuntu2.15, 2:9.0.1000-4ubuntu3.3, 2:9.0.1672-1ubuntu2.2
vim-gtk3 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.21, 2:8.2.3995-1ubuntu2.15, 2:9.0.1000-4ubuntu3.3, 2:9.0.1672-1ubuntu2.2
vim-athena (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.21, 2:8.2.3995-1ubuntu2.15, 2:9.0.1000-4ubuntu3.3, 2:9.0.1672-1ubuntu2.2
PowerStore X - update to 3.2.1.4-2386214
Storage Resource Manager - update to 4.10.0.3
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.3
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.0.1
Dell Secure Connect Gateway - update to 5.24.00.14
vim-common - addressed in versions 9.0-22, 9.0-23
vim-enhanced - addressed in versions 9.0-22, 9.0-23
vim-debuginfo - addressed in versions 9.0-22, 9.0-23
vim-debugsource - addressed in versions 9.0-22, 9.0-23
vim - addressed in versions 9.0-22, 9.0-23
vim-X11 - addressed in versions 9.0-22, 9.0-23
vim-filesystem - addressed in versions 9.0-22, 9.0-23
vim-minimal - addressed in versions 9.0-22, 9.0-23
vim-X11 - update to 9.0.2092-5
vim-common - update to 9.0.2092-5
vim-enhanced - update to 9.0.2092-5
vim-minimal - update to 9.0.2092-5
vim-data - update to 9.0.2092-5
vim-doc - update to 9.0.2092-5
vim-filesystem - update to 9.0.2092-5
vim - update to 9.0.2153-1
vim - addressed in versions 9.0.2167-1.fc38, 9.0.2167-1.fc39
vim-data - addressed in versions 9.1.0111-17.29.1, 9.1.0111-150500.20.9.1
vim-data-common - addressed in versions 9.1.0111-17.29.1, 9.1.0111-150500.20.9.1
vim - addressed in versions 9.1.0111-17.29.1, 9.1.0111-150500.20.9.1
gvim-debuginfo - addressed in versions 9.1.0111-17.29.1, 9.1.0111-150500.20.9.1
vim-debuginfo - addressed in versions 9.1.0111-17.29.1, 9.1.0111-150500.20.9.1
vim-debugsource - addressed in versions 9.1.0111-17.29.1, 9.1.0111-150500.20.9.1
gvim - addressed in versions 9.1.0111-17.29.1, 9.1.0111-150500.20.9.1
vim-small - update to 9.1.0111-150500.20.9.1
vim-small-debuginfo - update to 9.1.0111-150500.20.9.1
Oracle Solaris - update to 11.4 SRU 65
EMC Cloud Tiering Appliance - update to 13.2.0.2.29
External References
Related Security Bulletins
- Denial of service in Vim
- Ubuntu update for vim
- Fedora 39 update for vim
- Fedora 38 update for vim
- Oracle Solaris update for thrid-party components
- SUSE update for vim
- openEuler 22.03 LTS SP2 update for vim
- openEuler 20.03 LTS SP3 update for vim
- openEuler 20.03 LTS SP1 update for vim
- openEuler 22.03 LTS update for vim
- openEuler 22.03 LTS SP1 update for vim
- SUSE update for vim
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in Dell Data Protection Central
- Amazon Linux AMI update for vim
- Amazon Linux AMI update for vim
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Dell PowerStore X
- Anolis OS update for vim