CVE-2023-48237 Details
Description
Vim is an open source command line text editor. In affected versions when shifting lines in operator pending mode and using a very large value, it may be possible to overflow the size of integer. Impact is low, user interaction is required and a crash may not even happen in all situations. This issue has been addressed in commit `6bf131888` which has been included in version 9.0.2112. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| vim vim | < 9.0.2112 |
CPE
Remediation
| |
| fedoraproject fedora | 37 38 39 |
CPE
Remediation
| |
Change History
11 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jan 25, 2024 | Modified Analysis | [email protected] |
| Dec 27, 2023 | CVE Modified | [email protected] |
| Nov 26, 2023 | CVE Modified | [email protected] |
| Nov 24, 2023 | Initial Analysis | [email protected] |
| Nov 24, 2023 | CVE Modified | [email protected] |
| Nov 17, 2023 | CVE Modified | [email protected] |
| Nov 16, 2023 | New CVE Received | [email protected] |