Stack-based Buffer Overflow in vim/vim
Published Feb 17, 2022
7.8
HIGHCVSS 3.1
EPSS 1.87%
Description
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Affected products
-
Affected
- ≥ unspecified, < 8.2
Configuration 2
- 34
- 35
Configuration 4
- 10.0
No data.
Red Hat Enterprise Linux 6
vim
Not affected
Red Hat Enterprise Linux 7
vim
Not affected
Red Hat Enterprise Linux 8
vim
Not affected
Red Hat Enterprise Linux 9
vim
Not affected
Red Hat Virtualization 4
vim
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | vim | Not affected | n/a |
| Red Hat Enterprise Linux 7 | vim | Not affected | n/a |
| Red Hat Enterprise Linux 8 | vim | Not affected | n/a |
| Red Hat Enterprise Linux 9 | vim | Not affected | n/a |
| Red Hat Virtualization 4 | vim | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Vim is shipped in Red Hat Enterprise Linux with stack protection enabled that significantly minimize the impact of this vulnerability. Red Hat Product Security has rated this issue as having Moderate security impact. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Red Hat mitigation
Untrusted vim scripts with -s [scriptin] are not recommended to run.
References (14)
- http://seclists.org/fulldisclosure/2022/Oct/28 mailing-listMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2022/Oct/41 mailing-listMailing ListRelease NotesThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2022-0629 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2055695 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15726 Advisory
- https://github.com/vim/vim/commit/34f8117dec685ace52cd9e578e2729db278163fc PatchThird Party Advisory
- https://huntr.dev/bounties/95e2b0da-e480-4ee8-9324-a93a2ab0a877 ExploitPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/11/msg00032.html mailing-listThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7ZLEHVP4LNAGER4ZDGUDS5V5YVQD6INF/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UURGABNDL77YR5FRQKTFBYNBDQX2KO7Q/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-0629
- https://security.gentoo.org/glsa/202208-32 vendor-advisoryThird Party Advisory
- https://support.apple.com/kb/HT213488 Release NotesThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-0629
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data