PT-2022-3439 · Vim+8 · Vim+8
Brammool
·
Published
2022-05-16
·
Updated
2024-06-15
·
CVE-2022-1720
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
vim versions prior to 8.2.4956
Description
The issue is related to a buffer over-read in the
grab file name function in the vim text editor. This can cause the software to crash, allow memory modification, and potentially enable remote execution. An attacker could exploit this vulnerability by creating a special file and tricking the victim into opening it, leading to a buffer over-read error and allowing the attacker to read the contents of the system's memory.Recommendations
For versions prior to 8.2.4956, update to version 8.2.4956 or later to resolve the issue. As a temporary workaround, consider disabling the
grab file name function until a patch is available. Restrict access to files that could be used to exploit this vulnerability to minimize the risk of exploitation.Exploit
Fix
Buffer Over-read
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Linuxmint
Apple Macos
Red Os
Suse
Ubuntu
Vim