QID 355260

Date Published: 2023-05-29

QID 355260: Amazon Linux Security Advisory for vim : ALAS2023-2023-117

Heap-based buffer overflow in github repository vim/vim prior to 9.0.0483. (
( CVE-2022-3234) use after free in github repository vim/vim prior to 9.0.0490. (
( CVE-2022-3235) use after free in github repository vim/vim prior to 9.0.0530. (
( CVE-2022-3256) null pointer dereference in github repository vim/vim prior to 9.0.0552. (
( CVE-2022-3278) stack-based buffer overflow in github repository vim/vim prior to 9.0.0577. (
( CVE-2022-3296) use after free in github repository vim/vim prior to 9.0.0579. (
( CVE-2022-3297) stack-based buffer overflow in github repository vim/vim prior to 9.0.0598. (
( CVE-2022-3324) use after free in github repository vim/vim prior to 9.0.0614. (
( CVE-2022-3352) heap-based buffer overflow in github repository vim/vim prior to 9.0.0742. (
( CVE-2022-3491) a null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru 9.0.0339 allows attackers to cause denial of service or other unspecified impacts. (
( CVE-2022-47024)

Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Please refer to Amazon advisory: ALAS2023-2023-117 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ALAS2023-2023-117 amazon linux 2023 URL Logo alas.aws.amazon.com/AL2023/ALAS-2023-117.html