Use of out-of-range pointer offset in Vim - CVE-2022-0685
Published: February 22, 2022
Vulnerability identifier: #VU60774
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-0685
CWE-ID: CWE-823
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to crash the application.
The vulnerability exists due to improper input validation when processing special multi-byte characters. A remote attacker can trick the victim to open a specially crafted file and crash the application.
Affected software
Vim
Amazon Linux AMI
Gentoo Linux
Ubuntu
openEuler
Fedora
macOS
Isolation Segment
VMware Tanzu Application Service for VMs
vim (Ubuntu package)
vim-filesystem
vim-debuginfo
vim
vim-common
vim-debugsource
vim-enhanced
vim-X11
vim-minimal
app-editors/vim-core
app-editors/vim
app-editors/gvim
VMware Tanzu Operations Manager
Amazon Linux AMI
Gentoo Linux
Ubuntu
openEuler
Fedora
macOS
Isolation Segment
VMware Tanzu Application Service for VMs
vim (Ubuntu package)
vim-filesystem
vim-debuginfo
vim
vim-common
vim-debugsource
vim-enhanced
vim-X11
vim-minimal
app-editors/vim-core
app-editors/vim
app-editors/gvim
VMware Tanzu Operations Manager
How to mitigate CVE-2022-0685
Install updates from vendor's website.
Vim - update to 8.2.4418
vim (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:7.4.16893ubuntu1.5+esm6, 2:8.0.1453-1ubuntu1.13, 2:8.1.2269-1ubuntu5.14, 2:8.2.3995-1ubuntu2.7
VMware Tanzu Operations Manager - update to 3.0.8
vim-filesystem - update to 8.2-22
vim-debuginfo - update to 8.2-22
vim - update to 8.2-22
vim-common - update to 8.2-22
vim-debugsource - update to 8.2-22
vim-enhanced - update to 8.2-22
vim-X11 - update to 8.2-22
vim-minimal - update to 8.2-22
vim - addressed in versions 8.2.4428-1.fc34, 8.2.4460-1.fc34
app-editors/vim-core - update to 9.0.0060
app-editors/vim - update to 9.0.0060
app-editors/gvim - update to 9.0.0060
vim - update to 9.0.1160-1.1
macOS - update to 13.0 22A380
vim (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:7.4.16893ubuntu1.5+esm6, 2:8.0.1453-1ubuntu1.13, 2:8.1.2269-1ubuntu5.14, 2:8.2.3995-1ubuntu2.7
VMware Tanzu Operations Manager - update to 3.0.8
vim-filesystem - update to 8.2-22
vim-debuginfo - update to 8.2-22
vim - update to 8.2-22
vim-common - update to 8.2-22
vim-debugsource - update to 8.2-22
vim-enhanced - update to 8.2-22
vim-X11 - update to 8.2-22
vim-minimal - update to 8.2-22
vim - addressed in versions 8.2.4428-1.fc34, 8.2.4460-1.fc34
app-editors/vim-core - update to 9.0.0060
app-editors/vim - update to 9.0.0060
app-editors/gvim - update to 9.0.0060
vim - update to 9.0.1160-1.1
macOS - update to 13.0 22A380
External References
Related Security Bulletins
- Multiple vulnerabilities in Vim
- Amazon Linux AMI update for vim
- Ubuntu update for vim
- Gentoo update for Vim, gVim
- Multiple vulnerabilities in Apple macOS Ventura
- Ubuntu update for vim
- VMware Tanzu products update for Vim
- openEuler update for vim
- Amazon Linux AMI update for vim
- Fedora 34 update for vim
- Fedora 34 update for vim