CVE-2023-48234 Information

Description

Vim is an open source command line text editor. When getting the count for a normal mode z command it may overflow for large counts given. Impact is low user interaction is required and a crash may not even happen in all situations. This issue has been addressed in commit 58f9befca1 which has been included in release version 9.0.2109. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Reference

https://github.com/vim/vim/security/advisories/GHSA-59gw-c949-6phq https://github.com/vim/vim/commit/58f9befca1fa172068effad7f2ea5a9d6a7b0cca

Share on: