Use-after-free in Vim - CVE-2022-2042

 

Use-after-free in Vim - CVE-2022-2042

Published: June 27, 2022


Vulnerability identifier: #VU64706
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2042
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in spell.c. A remote attacker can trick the victim to open a specially crafted file, trigger a use-after-free error and execute arbitrary code on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

Vim
Amazon Linux AMI
Gentoo Linux
macOS
Ubuntu
openEuler
vim-nox (Ubuntu package)
vim-gtk3 (Ubuntu package)
vim-tiny (Ubuntu package)
vim-athena (Ubuntu package)
xxd (Ubuntu package)
vim (Ubuntu package)
vim-gtk (Ubuntu package)
vim-common
vim-enhanced
vim-X11
vim-filesystem
vim-minimal
vim
vim-debuginfo
vim-debugsource
app-editors/gvim
app-editors/vim
app-editors/vim-core
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data

How to mitigate CVE-2022-2042

Install updates from vendor's website.

Vim - update to 8.2.5072
macOS - addressed in versions 11.7 20G817, 12.6 21G115, 13.0 22A380
vim-nox (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.21, 2:8.2.3995-1ubuntu2.15, 2:9.0.1000-4ubuntu3.3, 2:9.0.1672-1ubuntu2.2
vim-gtk3 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.21, 2:8.2.3995-1ubuntu2.15, 2:9.0.1000-4ubuntu3.3, 2:9.0.1672-1ubuntu2.2
vim-tiny (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.21, 2:8.2.3995-1ubuntu2.15, 2:9.0.1000-4ubuntu3.3, 2:9.0.1672-1ubuntu2.2
vim-athena (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.21, 2:8.2.3995-1ubuntu2.15, 2:9.0.1000-4ubuntu3.3, 2:9.0.1672-1ubuntu2.2
xxd (Ubuntu package) - addressed in versions Ubuntu Pro, 2:8.1.2269-1ubuntu5.21, 2:8.2.3995-1ubuntu2.15, 2:9.0.1000-4ubuntu3.3, 2:9.0.1672-1ubuntu2.2
vim (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:7.4.16893ubuntu1.5+esm7, 2:8.1.2269-1ubuntu5.21, 2:8.2.3995-1ubuntu2.15, 2:9.0.1000-4ubuntu3.3, 2:9.0.1672-1ubuntu2.2
vim-gtk (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.21, 2:8.2.3995-1ubuntu2.15
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.0.1
vim-common - update to 8.2-42
vim-enhanced - update to 8.2-42
vim-X11 - update to 8.2-42
vim-filesystem - update to 8.2-42
vim-minimal - update to 8.2-42
vim - update to 8.2-42
vim-debuginfo - update to 8.2-42
vim-debugsource - update to 8.2-42
vim - addressed in versions 8.2.5172-1.1, 9.0.1160-1.1
app-editors/gvim - addressed in versions 9.0.0060, 9.0.1157
app-editors/vim - addressed in versions 9.0.0060, 9.0.1157
app-editors/vim-core - addressed in versions 9.0.0060, 9.0.1157

External References

Related Security Bulletins