Out-of-bounds read in Vim - CVE-2022-0368
Published: February 22, 2022
Vulnerability identifier: #VU60785
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-0368
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to crash the application.
The vulnerability exists due to a boundary condition. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger out-of-bounds read error and read contents of memory on the system.
Affected software
Vim
Amazon Linux AMI
Gentoo Linux
macOS
Ubuntu
openEuler
Isolation Segment
VMware Tanzu Application Service for VMs
Tanzu Greenplum for Kubernetes
Watson CP4D Data Stores
vim (Ubuntu package)
vim
vim-filesystem
vim-X11
vim-minimal
vim-debuginfo
vim-enhanced
vim-debugsource
vim-common
app-editors/vim
app-editors/gvim
app-editors/vim-core
VMware Tanzu Operations Manager
Amazon Linux AMI
Gentoo Linux
macOS
Ubuntu
openEuler
Isolation Segment
VMware Tanzu Application Service for VMs
Tanzu Greenplum for Kubernetes
Watson CP4D Data Stores
vim (Ubuntu package)
vim
vim-filesystem
vim-X11
vim-minimal
vim-debuginfo
vim-enhanced
vim-debugsource
vim-common
app-editors/vim
app-editors/gvim
app-editors/vim-core
VMware Tanzu Operations Manager
How to mitigate CVE-2022-0368
Install updates from vendor's website.
Vim - update to 8.2.4217
Tanzu Greenplum for Kubernetes - update to 2.0.0
macOS - addressed in versions 12.6 21G115, 13.0 22A380
vim (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:7.4.16893ubuntu1.5+esm5, 2:8.0.1453-1ubuntu1.13, 2:8.1.2269-1ubuntu5.14, 2:8.2.3995-1ubuntu2.7
VMware Tanzu Operations Manager - addressed in versions 2.9.41, 2.10.43, 3.0.8
Watson CP4D Data Stores - update to 5.0.3
vim - update to 8.2-16
vim-filesystem - update to 8.2-16
vim-X11 - update to 8.2-16
vim-minimal - update to 8.2-16
vim-debuginfo - update to 8.2-16
vim-enhanced - update to 8.2-16
vim-debugsource - update to 8.2-16
vim-common - update to 8.2-16
app-editors/vim - update to 9.0.0060
app-editors/gvim - update to 9.0.0060
app-editors/vim-core - update to 9.0.0060
vim - update to 9.0.1160-1.1
Tanzu Greenplum for Kubernetes - update to 2.0.0
macOS - addressed in versions 12.6 21G115, 13.0 22A380
vim (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:7.4.16893ubuntu1.5+esm5, 2:8.0.1453-1ubuntu1.13, 2:8.1.2269-1ubuntu5.14, 2:8.2.3995-1ubuntu2.7
VMware Tanzu Operations Manager - addressed in versions 2.9.41, 2.10.43, 3.0.8
Watson CP4D Data Stores - update to 5.0.3
vim - update to 8.2-16
vim-filesystem - update to 8.2-16
vim-X11 - update to 8.2-16
vim-minimal - update to 8.2-16
vim-debuginfo - update to 8.2-16
vim-enhanced - update to 8.2-16
vim-debugsource - update to 8.2-16
vim-common - update to 8.2-16
app-editors/vim - update to 9.0.0060
app-editors/gvim - update to 9.0.0060
app-editors/vim-core - update to 9.0.0060
vim - update to 9.0.1160-1.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Vim
- Ubuntu update for vim
- VMware Tanzu products update for Vim
- Gentoo update for Vim, gVim
- Multiple vulnerabilities in Apple macOS Ventura
- Multiple vulnerabilities in Apple macOS Monterey
- Ubuntu update for vim
- VMware Tanzu products update for Vim
- openEuler update for vim
- Amazon Linux AMI update for vim
- Multiple vulnerabilities in IBM Watson CP4D Data Stores