Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-2946

Опубликовано: 23 авг. 2022
Источник: redhat
CVSS3: 7.8

Описание

Use After Free in GitHub repository vim/vim prior to 9.0.0246.

A flaw was found in vim, where it is vulnerable to a use-after-free in the vim_vsnprintf_typval function. This flaw allows a specially crafted file to crash a program, use unexpected values, or execute code.

Отчет

To exploit CVE-2022-2946, an attacker must provide a specially crafted file to a user who then opens it using a vulnerable version of Vim. Successful exploitation can lead to arbitrary code execution or cause the application to crash, compromising the system's confidentiality, integrity, and availability. Considering user interaction is required and this vulnerabiltiy can only be exploited locally, RH ProdSec has set the Impact of this vulnerability to "Low"

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6vimOut of support scope
Red Hat Enterprise Linux 7vimOut of support scope
Red Hat Enterprise Linux 8vimFix deferred
Red Hat Enterprise Linux 9vimFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2120993vim: use after free in function vim_vsnprintf_typval

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 3 года назад

Use After Free in GitHub repository vim/vim prior to 9.0.0246.

CVSS3: 7.8
nvd
почти 3 года назад

Use After Free in GitHub repository vim/vim prior to 9.0.0246.

CVSS3: 7.8
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 7.8
debian
почти 3 года назад

Use After Free in GitHub repository vim/vim prior to 9.0.0246.

CVSS3: 7.8
github
почти 3 года назад

Use After Free in GitHub repository vim/vim prior to 9.0.0245.

7.8 High

CVSS3