Back

HIGH

Use After Free in vim/vim

Published Aug 23, 2022

Description

Use After Free in GitHub repository vim/vim prior to 9.0.0246.

Affected products

Remediation

Red Hat statement

To exploit CVE-2022-2946, an attacker must provide a specially crafted file to a user who then opens it using a vulnerable version of Vim. Successful exploitation can lead to arbitrary code execution or cause the application to crash, compromising the system's confidentiality, integrity, and availability. Considering user interaction is required and this vulnerabiltiy can only be exploited locally, RH ProdSec has set the Impact of this vulnerability to "Low"

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published Aug 23, 2022
Updated Aug 3, 2024
Reserved Aug 22, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Aug 23, 2022
ENISA EUVD
Assigner @huntrdev
Published Aug 23, 2022
Updated Aug 3, 2024
Exploited since n/a
EUVD-2022-35167