PT-2022-4639 · Vim+11 · Vim+11

Brammool

·

Published

2022-05-22

·

Updated

2024-06-15

·

CVE-2022-1927

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vim versions prior to 8.2
Description The issue is related to a buffer over-read in the Vim text editor. It is associated with the use of memory after it has been freed, which can be exploited to impact the confidentiality, integrity, and availability of protected information.
Recommendations For versions prior to 8.2, update to version 8.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the utf ptr2char() function until a patch is available.

Exploit

Fix

Out of bounds Read

Buffer Over-read

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:5813
ALSA-2022:5942
ALT-PU-2022-2001
ALT-PU-2022-2019
ALT-PU-2022-2420
ALT-PU-2022-2430
ALT-PU-2022-2616
ALT-PU-2022-2704
ALT-PU-2022-2714
ALT-PU-2022-3192
BDU:2022-05523
CESA-2022_5813
CVE-2022-1927
MGASA-2022-0223
OESA-2022-1707
OPENSUSE-SU-2022_2102-1
OPENSUSE-SU-2024:12337-1
RHSA-2022:5813
RHSA-2022:5942
RHSA-2022_5813
RHSA-2022_5942
RLSA-2022:5813
RLSA-2022:5942
SUSE-SU-2022:2102-1
SUSE-SU-2022:4619-1
USN-5995-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Apple Macos
Red Hat
Rocky Linux
Suse
Ubuntu
Vim