Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-3491

Опубликовано: 03 дек. 2022
Источник: redhat
CVSS3: 7.8

Описание

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742.

A heap-based buffer overflow flaw was found in Vim's skipwhite() function of the charset.c file. This issue occurs when reading data past the end of the line when compiling a function with errors. This could allows an attacker to trick a user into opening a specially crafted file, triggering an out-of-bounds read that causes an application to crash, leading to a denial of service.

Отчет

Red Hat Product Security has rated this issue as having a Low security impact, because the "victim" has to run an untrusted file in script mode. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/ and Red Hat Enterprise Linux Life Cycle & Updates Policy: https://access.redhat.com/support/policy/updates/errata/.

Меры по смягчению последствий

Untrusted vim scripts with -s [scriptin] are not recommended to run.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6vimNot affected
Red Hat Enterprise Linux 7vimNot affected
Red Hat Enterprise Linux 8vimNot affected
Red Hat Enterprise Linux 9vimNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-122->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2150770vim: Heap-based Buffer Overflow prior to 9.0.0742

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 3 лет назад

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742.

CVSS3: 7.8
nvd
около 3 лет назад

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742.

CVSS3: 7.8
debian
около 3 лет назад

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0 ...

CVSS3: 9.8
github
около 3 лет назад

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742.

CVSS3: 4
fstec
больше 3 лет назад

Уязвимость функции skipwhite (charset.c) текстового редактора Vim, позволяющая нарушителю вызвать отказ в обслуживании

7.8 High

CVSS3