Out-of-bounds write in Vim - CVE-2022-2000
Published: June 27, 2022
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input in ex_docmd.c. A remote attacker can create a specially crafted file, trick the victim into opening it using the affected software, trigger out-of-bounds write and execute arbitrary code on the target system.
Affected software
Amazon Linux AMI
Gentoo Linux
macOS
Ubuntu
openEuler
Fedora
vim-nox (Ubuntu package)
vim-gtk3 (Ubuntu package)
vim-tiny (Ubuntu package)
vim-athena (Ubuntu package)
xxd (Ubuntu package)
vim (Ubuntu package)
vim-gtk (Ubuntu package)
vim
vim-debuginfo
vim-debugsource
vim-enhanced
vim-minimal
vim-common
vim-X11
vim-filesystem
app-editors/gvim
app-editors/vim
app-editors/vim-core
How to mitigate CVE-2022-2000
macOS - addressed in versions 11.7 20G817, 12.6 21G115, 13.0 22A380
vim-nox (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.21, 2:8.2.3995-1ubuntu2.15, 2:9.0.1000-4ubuntu3.3, 2:9.0.1672-1ubuntu2.2
vim-gtk3 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.21, 2:8.2.3995-1ubuntu2.15, 2:9.0.1000-4ubuntu3.3, 2:9.0.1672-1ubuntu2.2
vim-tiny (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.21, 2:8.2.3995-1ubuntu2.15, 2:9.0.1000-4ubuntu3.3, 2:9.0.1672-1ubuntu2.2
vim-athena (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.21, 2:8.2.3995-1ubuntu2.15, 2:9.0.1000-4ubuntu3.3, 2:9.0.1672-1ubuntu2.2
xxd (Ubuntu package) - addressed in versions Ubuntu Pro, 2:8.1.2269-1ubuntu5.21, 2:8.2.3995-1ubuntu2.15, 2:9.0.1000-4ubuntu3.3, 2:9.0.1672-1ubuntu2.2
vim (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:7.4.16893ubuntu1.5+esm11, 2:8.1.2269-1ubuntu5.21, 2:8.2.3995-1ubuntu2.15, 2:9.0.1000-4ubuntu3.3, 2:9.0.1672-1ubuntu2.2
vim-gtk (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.21, 2:8.2.3995-1ubuntu2.15
vim - update to 8.2-42
vim-debuginfo - update to 8.2-42
vim-debugsource - update to 8.2-42
vim-enhanced - update to 8.2-42
vim-minimal - update to 8.2-42
vim-common - update to 8.2-42
vim-X11 - update to 8.2-42
vim-filesystem - update to 8.2-42
vim - update to 8.2.5085-1.fc35
vim - addressed in versions 8.2.5172-1.1, 9.0.1160-1.1
app-editors/gvim - addressed in versions 9.0.0060, 9.0.1157
app-editors/vim - addressed in versions 9.0.0060, 9.0.1157
app-editors/vim-core - addressed in versions 9.0.0060, 9.0.1157
External References
Related Security Bulletins
- Multiple vulnerabilities in Vim
- Ubuntu update for vim
- Amazon Linux AMI update for vim
- Gentoo update for Vim, gVim
- Multiple vulnerabilities in Apple macOS Ventura
- Multiple vulnerabilities in Apple macOS Big Sur
- Multiple vulnerabilities in Apple macOS Monterey
- Gentoo update for Vim, gVim
- Ubuntu update for vim
- openEuler update for vim
- Amazon Linux AMI update for vim
- Fedora 35 update for vim