CVE-2023-5535: Use After Free in vim/vim
Last updated 24 July 2024
Other sources
Use After Free in GitHub repository vim/vim prior to v9.0.2010.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/vimto a version that resolves this vulnerability.Fixed in 2:9.1.0496-1Fixed in 2:9.1.0709-1 - Upgrade
Upgrade
vim/vimto a version that resolves this vulnerability.Fixed in v9.0.2010
Event History
Frequently Asked Questions
What is CVE-2023-5535?
CVE-2023-5535 is a vulnerability in the GitHub repository vim/vim prior to v9.0.2010, which allows for a Use After Free exploit.
What software is affected by CVE-2023-5535?
Vim Vim versions prior to v9.0.2010 are affected by CVE-2023-5535.
What is the severity of CVE-2023-5535?
CVE-2023-5535 has a severity rating of 7.8 (high).
How can I fix CVE-2023-5535?
To fix CVE-2023-5535, update your Vim Vim software to version v9.0.2010 or later, which includes the necessary security patches.
Where can I find more information about CVE-2023-5535?
You can find more information about CVE-2023-5535 at the following references: [GitHub Commit](https://github.com/vim/vim/commit/41e6f7d6ba67b61d911f9b1d76325cd79224753d) and [Huntr.dev](https://huntr.dev/bounties/2c2d85a7-1171-4014-bf7f-a2451745861f).