Use After Free in vim/vim
Published Aug 23, 2022
7.8
HIGHCVSS 3.1
EPSS 0.53%
Description
Use After Free in GitHub repository vim/vim prior to 9.0.0246.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<9.0.0246
- Version
Configuration 2
- 35
Configuration 3
- 10.0
No data.
Red Hat Enterprise Linux 6
vim
Out of support scope
Red Hat Enterprise Linux 7
vim
Out of support scope
Red Hat Enterprise Linux 8
vim
Fix deferred
Red Hat Enterprise Linux 9
vim
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | vim | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | vim | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | vim | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | vim | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
To exploit CVE-2022-2946, an attacker must provide a specially crafted file to a user who then opens it using a vulnerable version of Vim. Successful exploitation can lead to arbitrary code execution or cause the application to crash, compromising the system's confidentiality, integrity, and availability. Considering user interaction is required and this vulnerabiltiy can only be exploited locally, RH ProdSec has set the Impact of this vulnerability to "Low"
References (10)
- https://access.redhat.com/security/cve/CVE-2022-2946 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2120993 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-35167 Advisory
- https://github.com/vim/vim/commit/adce965162dd89bf29ee0e5baf53652e7515762c PatchThird Party Advisory
- https://huntr.dev/bounties/5d389a18-5026-47df-a5d0-1548a9b555d5 ExploitPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html mailing-listMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C72HDIMR3KTTAO7QGTXWUMPBNFUFIBRD/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-2946
- https://security.gentoo.org/glsa/202305-16 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2022-2946
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-2946 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2120993 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-35167 | Advisory | |
| https://github.com/vim/vim/commit/adce965162dd89bf29ee0e5baf53652e7515762c | PatchThird Party Advisory | |
| https://huntr.dev/bounties/5d389a18-5026-47df-a5d0-1548a9b555d5 | ExploitPatchThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html | mailing-listMailing ListThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C72HDIMR3KTTAO7QGTXWUMPBNFUFIBRD/ | vendor-advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-2946 | ||
| https://security.gentoo.org/glsa/202305-16 | vendor-advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-2946 |
Change history (0)
No recorded changes yet.