#VU65395 Stack-based buffer overflow in Vim - CVE-2022-2304
Published: July 18, 2022 / Updated: July 19, 2022
Vim
Vim.org
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in spell_dump_compl() function at spell.c:4038. A remote unauthenticated attacker can trick the victim into opening a specially crafted file to trigger stack-based buffer overflow and execute arbitrary code on the target system.