PT-2022-2754 · Vim+8 · Vim+8
Brammool
·
Published
2022-04-28
·
Updated
2025-03-30
·
CVE-2022-1616
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vim versions prior to 8.2.4895
Description
The issue is related to a use after free vulnerability in the append command function of the Vim text editor. This vulnerability can cause software crashes, bypass protection mechanisms, modify memory, and potentially allow for remote execution. An attacker could exploit this vulnerability by tricking a user into opening a specially crafted file, leading to a heap buffer overflow and the execution of arbitrary code on the target system.
Recommendations
For versions prior to 8.2.4895, update to version 8.2.4895 or later to resolve the issue.
As a temporary workaround, consider avoiding the use of the append command function until a patch is available.
Restrict access to specially crafted files that could exploit the vulnerability to minimize the risk of exploitation.
Exploit
Fix
Use After Free
Heap Based Buffer Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Linuxmint
Apple Macos
Red Os
Suse
Ubuntu
Vim