CVE-2022-1629

Name
CVE-2022-1629
Description
Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are capable of crashing software, Modify Memory, and possible remote execution
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/vim/vim/commit/53a70289c2712808e6d4e88927e03cac01b470dd
CONFIRM https://huntr.dev/bounties/e26d08d4-1886-41f0-9af4-f3e1bf3d52ee
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HIP7KG7TVS5YF3QREAY2GOGUT3YUBZAI/
Third Party Advisory https://security.gentoo.org/glsa/202208-32
Third Party Advisory https://support.apple.com/kb/HT213488
Mailing List http://seclists.org/fulldisclosure/2022/Oct/41
Third Party Advisory https://security.gentoo.org/glsa/202305-16
Mailing List http://seclists.org/fulldisclosure/2022/Oct/28
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HIP7KG7TVS5YF3QREAY2GOGUT3YUBZAI/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:* vim >= None < 8.2.4925

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
vim 3.14-main 8.2.4836-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
vim 3.13-main 8.2.4836-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
vim 3.12-main 8.2.4836-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
vim 3.15-main 8.2.4836-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable