Описание
Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer, causing the error path to read freed memory instead of reader->js_buf + reader->js_used when an invalid JSON string spans buffers. This issue is fixed in version 9.2.0844.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 2:9.2.0858-1ubuntu1 |
| esm-infra-legacy/trusty | not-affected | code not present |
| esm-infra-legacy/xenial | not-affected | code not present |
| esm-infra/bionic | not-affected | code not present |
| esm-infra/focal | not-affected | code not present |
| jammy | released | 2:8.2.3995-1ubuntu2.35 |
| noble | released | 2:9.1.0016-1ubuntu7.19 |
| resolute | released | 2:9.1.2141-1ubuntu4.8 |
| upstream | released | 2:9.2.0858-1 |
Показывать по
Ссылки на источники
EPSS
3.3 Low
CVSS3
Связанные уязвимости
Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer, causing the error path to read freed memory instead of reader->js_buf + reader->js_used when an invalid JSON string spans buffers. This issue is fixed in version 9.2.0844.
Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer, causing the error path to read freed memory instead of reader->js_buf + reader->js_used when an invalid JSON string spans buffers. This issue is fixed in version 9.2.0844.
Vim is an open source, command line text editor. From 9.2.0511 until 9 ...
EPSS
3.3 Low
CVSS3