CVE-2022-1381

Name
CVE-2022-1381
Description
global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://huntr.dev/bounties/55f9c0e8-c221-48b6-a00e-bdcaebaba4a4
MISC https://github.com/vim/vim/commit/f50808ed135ab973296bca515ae4029b321afe47
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6E457NYOIRWBJHKB7ON44UY5AVTG4HU/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KVPZVE2CIE2NGCHZDMEHPBWN3LK2UQAA/
Third Party Advisory https://security.gentoo.org/glsa/202208-32
Release Notes https://support.apple.com/kb/HT213488
Mailing List http://seclists.org/fulldisclosure/2022/Oct/41
FULLDISC http://seclists.org/fulldisclosure/2022/Oct/28
GENTOO https://security.gentoo.org/glsa/202305-16
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6E457NYOIRWBJHKB7ON44UY5AVTG4HU/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KVPZVE2CIE2NGCHZDMEHPBWN3LK2UQAA/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:* vim >= None < 8.2.4763

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
vim 3.14-main 8.2.4836-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
vim 3.13-main 8.2.4836-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
vim 3.12-main 8.2.4836-r0 Natanael Copa <ncopa@alpinelinux.org> fixed