PT-2022-2732 · Vim+7 · Vim+7

Brammool

·

Published

2022-05-16

·

Updated

2024-06-15

·

CVE-2022-1796

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vim versions prior to 8.2.4979
Description The issue is related to a Use After Free error in the Vim text editor. This error is associated with the find pattern in path() function and involves the use of memory after it has been freed. Exploitation of this issue may allow an attacker to execute arbitrary code or cause a denial of service by using a specially crafted file. The attacker could potentially trick a victim into opening this file, leading to the execution of arbitrary code in the target system.
Recommendations For versions prior to 8.2.4979, update to version 8.2.4979 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for this vulnerability.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1948
ALT-PU-2022-1958
ALT-PU-2022-1977
ALT-PU-2022-1987
AZL-9791
BDU:2022-03237
CVE-2022-1796
OESA-2022-1699
OPENSUSE-SU-2022_2102-1
OPENSUSE-SU-2024:12337-1
SUSE-SU-2022:2102-1
SUSE-SU-2022:4619-1
USN-5498-1
USN-5995-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Red Os
Suse
Ubuntu
Vim