Floating point Exception in adjust_plines_for_skipcol() in vim
Published Nov 16, 2023
4.3
MEDIUMCVSS 3.1
EPSS 0.67%
Description
Vim is an open source command line text editor. A floating point exception may occur when calculating the line offset for overlong lines and smooth scrolling is enabled and the cpo-settings include the 'n' flag. This may happen when a window border is present and when the wrapped line continues on the next physical line directly in the window border because the 'cpo' setting includes the 'n' flag. Only users with non-default settings are affected and the exception should only result in a crash. This issue has been addressed in commit `cb0b99f0` which has been included in release version 9.0.2107. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected products
-
Affected
- < 9.0.2107
Configuration 2
- 37
- 38
- 39
No data.
Red Hat Enterprise Linux 6
vim
Out of support scope
Red Hat Enterprise Linux 7
vim
Out of support scope
Red Hat Enterprise Linux 8
vim
Fix deferred
Red Hat Enterprise Linux 9
vim
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | vim | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | vim | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | vim | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | vim | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
All versions of Vim shipped with Red Hat Enterprise Linux are affected, because of the presence of vulnerable code in our code-base. Red Hat Product Security has rated this issue as having a Low security impact, because the "victim" has to run an untrusted file IN SCRIPT MODE. Someone who is running untrusted files in script mode is equivalent to someone just taking a random python script and running it. Since Red Hat Enterprise Linux 6, 7 are Out-of-Support-Scope for Low/Moderate flaws, the issue is not currently planned to be addressed in future updates for RHEL-6,7. Only Important and Critical severity flaws will be addressed at this time. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/ and Red Hat Enterprise Linux Life Cycle & Updates Policy: https://access.redhat.com/support/policy/updates/errata/.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (12)
- http://www.openwall.com/lists/oss-security/2023/11/16/1 Mailing List
- https://access.redhat.com/security/cve/CVE-2023-48232 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2250269 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-52304 Advisory
- https://github.com/vim/vim/commit/cb0b99f0672d8446585d26e998343dceca17d1ce x_refsource_MISCPatch
- https://github.com/vim/vim/security/advisories/GHSA-f6cx-x634-hqpw x_refsource_CONFIRMVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4UJAK2W5S7G75ETDAEM3BDUCVSXCEGRD/ Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M3VQF7CL3V6FGSEW37WNDFBRRILR65AK/ Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VNRNYLWXZOGTYWE5HMFNQ5FVE3HBUHF6/ Mailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-48232
- https://security.netapp.com/advisory/ntap-20231227-0006/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-48232
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data