Use After Free in vim/vim
Published Sep 18, 2022
7.8
HIGHCVSS 3.1
EPSS 0.51%
Description
Use After Free in GitHub repository vim/vim prior to 9.0.0490.
Affected products
-
Affected
- ≥ unspecified, < 9.0.0490
Configuration 2
- 35
- 36
- 37
Configuration 3
- 10.0
No data.
Red Hat Enterprise Linux 6
vim
Out of support scope
Red Hat Enterprise Linux 7
vim
Out of support scope
Red Hat Enterprise Linux 8
vim
Fix deferred
Red Hat Enterprise Linux 9
vim
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | vim | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | vim | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | vim | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | vim | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security has rated this issue as having a Low security impact, because the "victim" has to run an untrusted file IN SCRIPT MODE. Someone who is running untrusted files in script mode is equivalent to someone just taking a random python script and running it.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (12)
- https://access.redhat.com/security/cve/CVE-2022-3235 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2129371 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42643 Advisory
- https://github.com/vim/vim/commit/1c3dd8ddcba63c1af5112e567215b3cec2de11d0 PatchThird Party Advisory
- https://huntr.dev/bounties/96d5f7a0-a834-4571-b73b-0fe523b941af ExploitPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/11/msg00032.html mailing-listMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4QI7AETXBHPC7SGA77Q7O5IEGULWYET7/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTBVD4J2SKVSWK4VBN5JP5OEVK6GDS3N/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LSSEWQLK55MCNT4Z2IIJEJYEI5HLCODI/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3235
- https://security.gentoo.org/glsa/202305-16 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2022-3235
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data