• CVE-2024-41957

发布时间: 2024年8月16日

修改时间: 2024年10月9日

概要

Vim is an open source command line text editor. Vim < v9.1.0647 has double free in src/alloc.c:616. When closing a window, the corresponding tagstack data will be cleared and freed. However a bit later, the quickfix list belonging to that window will also be cleared and if that quickfix list points to the same tagstack data, Vim will try to free it again, resulting in a double-free/use-after-free access exception. Impact is low since the user must intentionally execute vim with several non-default flags,but it may cause a crash of Vim. The issue has been fixed as of Vim patch v9.1.0647

CVSS v3 指标

NVD openEuler
CVSS评分 5.3 5.3
Attack Vector Local Local
Attack Complexity Low Low
Privileges Required None None
User Interaction Required Required
Scope Unchanged Unchanged
Confidentiality Low Low
Integrity Low Low
Availability Low Low

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-3681 vim security update 2024年8月16日

影响产品

产品 状态
KY3.4-5A vim Fixed
KY3.5.2 vim Fixed
V6 vim Fixed