Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog
Консоль
Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog

exploitDog

redhat Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

CVE-2022-2124

ΠžΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ: 19 июн. 2022
Π˜ΡΡ‚ΠΎΡ‡Π½ΠΈΠΊ: redhat
CVSS3: 7.8
EPSS Низкий

ОписаниС

Buffer Over-read in GitHub repository vim/vim prior to 8.2.

ΠžΡ‚Ρ‡Π΅Ρ‚

Red Hat Product Security has rated this issue as having a Low security impact, because the "victim" has to run an untrusted file IN SCRIPT MODE. Someone who is running untrusted files in script mode is equivalent to someone just taking a random python script and running it. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/ Red Hat Enterprise Linux 6 and 7 are out of support scope for this flaw. To learn more about RHEL support scopes, please see https://access.redhat.com/support/policy/updates/errata/ .

Π—Π°Ρ‚Ρ€ΠΎΠ½ΡƒΡ‚Ρ‹Π΅ ΠΏΠ°ΠΊΠ΅Ρ‚Ρ‹

ΠŸΠ»Π°Ρ‚Ρ„ΠΎΡ€ΠΌΠ°ΠŸΠ°ΠΊΠ΅Ρ‚Π‘ΠΎΡΡ‚ΠΎΡΠ½ΠΈΠ΅Π Π΅ΠΊΠΎΠΌΠ΅Π½Π΄Π°Ρ†ΠΈΡΠ Π΅Π»ΠΈΠ·
Red Hat Enterprise Linux 6vimOut of support scope
Red Hat Enterprise Linux 7vimOut of support scope
Red Hat Enterprise Linux 8vimFix deferred
Red Hat Enterprise Linux 9vimFix deferred

ΠŸΠΎΠΊΠ°Π·Ρ‹Π²Π°Ρ‚ΡŒ ΠΏΠΎ

Бсылки Π½Π° источники

Π”ΠΎΠΏΠΎΠ»Π½ΠΈΡ‚Π΅Π»ΡŒΠ½Π°Ρ информация

Бтатус:

Low
Π”Π΅Ρ„Π΅ΠΊΡ‚:
CWE-126
https://bugzilla.redhat.com/show_bug.cgi?id=2099558vim: out of bounds read in current_quote()

EPSS

ΠŸΡ€ΠΎΡ†Π΅Π½Ρ‚ΠΈΠ»ΡŒ: 45%
0.00227
Низкий

7.8 High

CVSS3

БвязанныС уязвимости

CVSS3: 7.8
ubuntu
большС 3 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

Buffer Over-read in GitHub repository vim/vim prior to 8.2.

CVSS3: 7.8
nvd
большС 3 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

Buffer Over-read in GitHub repository vim/vim prior to 8.2.

CVSS3: 7.8
msrc
большС 3 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

Buffer Over-read in vim/vim

CVSS3: 7.8
debian
большС 3 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

Buffer Over-read in GitHub repository vim/vim prior to 8.2.

CVSS3: 7.8
github
большС 3 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

Buffer Over-read in GitHub repository vim/vim prior to 8.2.

EPSS

ΠŸΡ€ΠΎΡ†Π΅Π½Ρ‚ΠΈΠ»ΡŒ: 45%
0.00227
Низкий

7.8 High

CVSS3

Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡ‚ΡŒ CVE-2022-2124