PT-2022-1740 · Vim+10 · Vim+10

Brammool

·

Published

2022-01-30

·

Updated

2024-06-15

·

CVE-2022-0413

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vim versions prior to 8.2
Description The issue is related to a use after free error in the src/ex cmds.c component of the vim text editor, which involves the use of memory after it has been freed. This could allow an attacker to execute arbitrary code.
Recommendations For versions prior to 8.2, update to version 8.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the src/ex cmds.c component until a patch is available.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:0894
ALT-PU-2022-1693
ALT-PU-2022-1711
ALT-PU-2022-1731
ALT-PU-2022-1771
AZL-8460
BDU:2022-01016
CESA-2022_0894
CVE-2022-0413
DLA-3011-1
DLA-3182-1
MGASA-2022-0203
OESA-2022-1514
OPENSUSE-SU-2022:0736-1
OPENSUSE-SU-2022_0736-1
OPENSUSE-SU-2022_2102-1
OPENSUSE-SU-2024:12337-1
RHSA-2022:0894
RHSA-2022_0894
RLSA-2022:0894
SUSE-SU-2022:0736-1
SUSE-SU-2022:0736-2
SUSE-SU-2022:2102-1
SUSE-SU-2022:4619-1
USN-5498-1
USN-5995-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Vim