PT-2022-3439 · Vim+8 · Vim+8

Brammool

·

Published

2022-05-16

·

Updated

2024-06-15

·

CVE-2022-1720

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vim versions prior to 8.2.4956
Description The issue is related to a buffer over-read in the grab file name function in the vim text editor. This can cause the software to crash, allow memory modification, and potentially enable remote execution. An attacker could exploit this vulnerability by creating a special file and tricking the victim into opening it, leading to a buffer over-read error and allowing the attacker to read the contents of the system's memory.
Recommendations For versions prior to 8.2.4956, update to version 8.2.4956 or later to resolve the issue. As a temporary workaround, consider disabling the grab file name function until a patch is available. Restrict access to files that could be used to exploit this vulnerability to minimize the risk of exploitation.

Exploit

Fix

Buffer Over-read

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1948
ALT-PU-2022-1958
ALT-PU-2022-1977
ALT-PU-2022-1987
BDU:2022-04217
CVE-2022-1720
DLA-3053-1
DLA-3182-1
OESA-2022-1749
OPENSUSE-SU-2022_3229-1
OPENSUSE-SU-2024:12337-1
SUSE-SU-2022:3229-1
SUSE-SU-2022:4619-1
SUSE-SU-2022_3229-1
USN-5995-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Apple Macos
Red Os
Suse
Ubuntu
Vim