Heap-based buffer overflow in Vim - CVE-2022-1160

 

Heap-based buffer overflow in Vim - CVE-2022-1160

Published: April 15, 2022


Vulnerability identifier: #VU62360
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1160
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the get_one_sourceline() function. A remote attacker can trick the victim to open a specially crafted file, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Vim
Arch Linux
Amazon Linux AMI
Gentoo Linux
Fedora
vim
app-editors/gvim
app-editors/vim
app-editors/vim-core

How to mitigate CVE-2022-1160

Install updates from vendor's website.

Vim - update to 8.2.4647
vim - addressed in versions 8.2.4701-1.fc34, 8.2.4701-1.fc35, 8.2.4701-1.fc36
app-editors/gvim - addressed in versions 9.0.0060, 9.0.1157
app-editors/vim - addressed in versions 9.0.0060, 9.0.1157
app-editors/vim-core - addressed in versions 9.0.0060, 9.0.1157
vim - update to 9.0.1160-1.1

External References

Related Security Bulletins