CVE-2022-0729
Published: August 31, 2023Last modified: August 31, 2023
Description
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.
Severity score breakdown
Parameter | Value |
---|---|
Base score | 8.8 |
Attack Vector | NETWORK |
Attack complexity | LOW |
Privileges required | LOW |
User interaction | NONE |
Scope | UNCHANGED |
Confidentiality | HIGH |
Integrity impact | HIGH |
Availability impact | HIGH |
Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Status
Product | Release | Package | Status |
---|---|---|---|
Alpaquita Linux | 23 LTS | vim | Not affected (9.0.0999-r0) |
Stream | vim | Not affected (9.0.1676-r0) |
References
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- https://github.com/vim/vim/commit/6456fae9ba8e72c74b2c0c499eaf09974604ff30
- https://huntr.dev/bounties/f3f3d992-7bd6-4ee5-a502-ae0e5f8016ea
- https://lists.debian.org/debian-lts-announce/2022/03/msg00018.html
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7ZLEHVP4LNAGER4ZDGUDS5V5YVQD6INF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HBUYQBZ6GWAWJRWP7AODJ4KHW5BCKDVP/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/7ZLEHVP4LNAGER4ZDGUDS5V5YVQD6INF/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/HBUYQBZ6GWAWJRWP7AODJ4KHW5BCKDVP/
- https://security.gentoo.org/glsa/202208-32
- https://support.apple.com/kb/HT213488