PT-2022-4855 · Vim+8 · Vim+8
Published
2022-01-10
·
Updated
2024-06-15
·
CVE-2022-0554
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Vim versions prior to 8.2
Description
The issue is related to the
enter buffer() function in the Vim text editor, which is associated with an out-of-bounds pointer offset. This allows a remote attacker to access confidential data, compromise its integrity, and cause a denial of service. The estimated number of potentially affected devices worldwide is not specified.Recommendations
For versions prior to 8.2, update to version 8.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
enter buffer() function until a patch is available.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Debian
Linuxmint
Apple Macos
Red Hat
Ubuntu
Vim