CVE-2024-47814
CVSS V2 None
CVSS V3 None
Description
Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) a BufWinLeave auto command can cause an use-after-free if this auto command happens to re-open the same buffer in a new split window. Impact is low since the user must have intentionally set up such a strange auto command and run some buffer unload commands. However this may lead to a crash. This issue has been addressed in version 9.1.0764 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Overview
- CVE ID
- CVE-2024-47814
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-10-07T21:16:01.796Z
- Last Modified Date
- 2024-10-07T21:16:01.796Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/vim/vim/security/advisories/GHSA-rj48-v4mq-j4vg | x_refsource_CONFIRM |
https://github.com/vim/vim/commit/51b62387be93c65fa56bbabe1c3 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-47814 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-47814 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-10-08 13:22:20 | Added to TrackCVE |