Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-2946

Опубликовано: 23 авг. 2022
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

Use After Free in GitHub repository vim/vim prior to 9.0.0246.

A flaw was found in vim, where it is vulnerable to a use-after-free in the vim_vsnprintf_typval function. This flaw allows a specially crafted file to crash a program, use unexpected values, or execute code.

Отчет

To exploit CVE-2022-2946, an attacker must provide a specially crafted file to a user who then opens it using a vulnerable version of Vim. Successful exploitation can lead to arbitrary code execution or cause the application to crash, compromising the system's confidentiality, integrity, and availability. Considering user interaction is required and this vulnerabiltiy can only be exploited locally, RH ProdSec has set the Impact of this vulnerability to "Low"

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6vimOut of support scope
Red Hat Enterprise Linux 7vimOut of support scope
Red Hat Enterprise Linux 8vimFix deferred
Red Hat Enterprise Linux 9vimFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2120993vim: use after free in function vim_vsnprintf_typval

EPSS

Процентиль: 7%
0.00031
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 3 лет назад

Use After Free in GitHub repository vim/vim prior to 9.0.0246.

CVSS3: 7.8
nvd
около 3 лет назад

Use After Free in GitHub repository vim/vim prior to 9.0.0246.

CVSS3: 7.8
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 7.8
debian
около 3 лет назад

Use After Free in GitHub repository vim/vim prior to 9.0.0246.

CVSS3: 7.8
github
около 3 лет назад

Use After Free in GitHub repository vim/vim prior to 9.0.0245.

EPSS

Процентиль: 7%
0.00031
Низкий

7.8 High

CVSS3