NULL Pointer Dereference in vim/vim
Published Feb 21, 2022
5.5
MEDIUMCVSS 3.1
EPSS 1.51%
Description
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<8.2.4428
- Version
Configuration 2
- 34
Configuration 4
- 10.0
No data.
Red Hat Enterprise Linux 6
vim
Not affected
Red Hat Enterprise Linux 7
vim
Not affected
Red Hat Enterprise Linux 8
vim
Not affected
Red Hat Enterprise Linux 9
vim
Not affected
Red Hat Virtualization 4
vim
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | vim | Not affected | n/a |
| Red Hat Enterprise Linux 7 | vim | Not affected | n/a |
| Red Hat Enterprise Linux 8 | vim | Not affected | n/a |
| Red Hat Enterprise Linux 9 | vim | Not affected | n/a |
| Red Hat Virtualization 4 | vim | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The versions of vim shipped in Red Hat Enterprise Linux are not affected, because vulnerable code is not present in our code-base as it is a little different and secured than upstream. Red Hat Product Security has rated this issue as having a Moderate security impact. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Red Hat mitigation
Untrusted vim scripts with -s [scriptin] are not recommended to run.
References (12)
- http://seclists.org/fulldisclosure/2022/Oct/28 mailing-listMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2022/Oct/41 mailing-listMailing ListRelease NotesThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2022-0696 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2056805 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15775 Advisory
- https://github.com/vim/vim/commit/0f6e28f686dbb59ab3b562408ab9b2234797b9b1 PatchThird Party Advisory
- https://huntr.dev/bounties/7416c2cb-1809-4834-8989-e84ff033f15f ExploitThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/11/msg00032.html mailing-listMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7ZLEHVP4LNAGER4ZDGUDS5V5YVQD6INF/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-0696
- https://support.apple.com/kb/HT213488 Release NotesThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-0696
Change history (0)
No recorded changes yet.