PT-2022-2754 · Vim+8 · Vim+8

Brammool

·

Published

2022-04-28

·

Updated

2025-03-30

·

CVE-2022-1616

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vim versions prior to 8.2.4895
Description The issue is related to a use after free vulnerability in the append command function of the Vim text editor. This vulnerability can cause software crashes, bypass protection mechanisms, modify memory, and potentially allow for remote execution. An attacker could exploit this vulnerability by tricking a user into opening a specially crafted file, leading to a heap buffer overflow and the execution of arbitrary code on the target system.
Recommendations For versions prior to 8.2.4895, update to version 8.2.4895 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the append command function until a patch is available. Restrict access to specially crafted files that could exploit the vulnerability to minimize the risk of exploitation.

Exploit

Fix

Use After Free

Heap Based Buffer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1948
ALT-PU-2022-1958
ALT-PU-2022-1977
ALT-PU-2022-1987
AZL-9737
BDU:2022-03271
CVE-2022-1616
DLA-3011-1
DLA-3182-1
DLA-4097-1
MGASA-2022-0203
OESA-2022-1656
OPENSUSE-SU-2022_2102-1
OPENSUSE-SU-2024:12337-1
SUSE-SU-2022:2102-1
SUSE-SU-2022:4619-1
USN-5460-1
USN-5613-1
USN-5613-2

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Apple Macos
Red Os
Suse
Ubuntu
Vim