Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-4293

Опубликовано: 02 дек. 2022
Источник: redhat
CVSS3: 5.5

Описание

Floating Point Comparison with Incorrect Operator in GitHub repository vim/vim prior to 9.0.0804.

A floating point exception flaw was found in Vim's num_divide() function of the eval.c file. This issue occurs when dividing the largest negative number by -1. This could allow an attacker to trick a user into opening a specially crafted file, triggering an application to crash and leading to a denial of service.

Отчет

Red Hat Product Security has rated this issue as having a Low security impact, because the "victim" has to run an untrusted file in script mode. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/ and Red Hat Enterprise Linux Life Cycle & Updates Policy: https://access.redhat.com/support/policy/updates/errata/.

Меры по смягчению последствий

Untrusted vim scripts with -s [scriptin] are not recommended to run.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6vimNot affected
Red Hat Enterprise Linux 7vimNot affected
Red Hat Enterprise Linux 8vimFix deferred
Red Hat Enterprise Linux 9vimFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-697
Дефект:
CWE-1077
https://bugzilla.redhat.com/show_bug.cgi?id=2151566vim: floating point exception in num_divide() in src/eval.c

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 3 лет назад

Floating Point Comparison with Incorrect Operator in GitHub repository vim/vim prior to 9.0.0804.

CVSS3: 5.5
nvd
около 3 лет назад

Floating Point Comparison with Incorrect Operator in GitHub repository vim/vim prior to 9.0.0804.

CVSS3: 5.5
debian
около 3 лет назад

Floating Point Comparison with Incorrect Operator in GitHub repository ...

CVSS3: 5.5
github
около 3 лет назад

Floating Point Comparison with Incorrect Operator in GitHub repository vim/vim prior to 9.0.0804.

CVSS3: 6.8
fstec
больше 3 лет назад

Уязвимость функции num_divide (eval.c) текстового редактора Vim, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании

5.5 Medium

CVSS3