CVE-2023-5535: Use After Free in vim/vim
Published Oct 11, 2023
·Updated
Last updated 24 July 2024
Other sources
Use After Free in GitHub repository vim/vim prior to v9.0.2010.
Affected Software
5 affected componentsFixes available
debian/vim<=2:8.2.2434-3+deb11u1, <=2:9.0.1378-2
2:9.1.0496-12:9.1.0709-1
vim Vim<9.0.2010
Fedoraproject Fedora=37
Fedoraproject Fedora=38
Fedoraproject Fedora=39
Remediation
Event History
Oct 11, 2023
CVE Published
via MITRE·07:12 PM
Data Sourced
via MITRE·07:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 12, 2024
Data Sourced
via Launchpad·12:28 AM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·04:18 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2023-5535?
CVE-2023-5535 is a vulnerability in the GitHub repository vim/vim prior to v9.0.2010, which allows for a Use After Free exploit.
2
What software is affected by CVE-2023-5535?
Vim Vim versions prior to v9.0.2010 are affected by CVE-2023-5535.
3
What is the severity of CVE-2023-5535?
CVE-2023-5535 has a severity rating of 7.8 (high).
4
How can I fix CVE-2023-5535?
To fix CVE-2023-5535, update your Vim Vim software to version v9.0.2010 or later, which includes the necessary security patches.
5
Where can I find more information about CVE-2023-5535?
You can find more information about CVE-2023-5535 at the following references: [GitHub Commit](https://github.com/vim/vim/commit/41e6f7d6ba67b61d911f9b1d76325cd79224753d) and [Huntr.dev](https://huntr.dev/bounties/2c2d85a7-1171-4014-bf7f-a2451745861f).