Use-after-free in Vim - CVE-2022-2289

 

Use-after-free in Vim - CVE-2022-2289

Published: July 18, 2022 / Updated: July 19, 2022


Vulnerability identifier: #VU65399
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2289
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in ex_diffgetput() function at diff.c:2790. A remote attacker can trick the victim into opening a specially crafted file and compromise vulnerable system.


Affected software

Vim
Gentoo Linux
Amazon Linux AMI
Ubuntu
openEuler
Fedora
Isolation Segment
VMware Tanzu Application Service for VMs
vim-athena (Ubuntu package)
vim (Ubuntu package)
vim-gtk (Ubuntu package)
vim-tiny (Ubuntu package)
xxd (Ubuntu package)
vim-gtk3 (Ubuntu package)
vim-nox (Ubuntu package)
vim-filesystem
vim
vim-debugsource
vim-enhanced
vim-X11
vim-debuginfo
vim-common
vim-minimal
app-editors/vim-core
app-editors/vim
app-editors/gvim
VMware Tanzu Operations Manager

How to mitigate CVE-2022-2289

Install updates from vendor's website.

Vim - update to 9.0.0026
vim-athena (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.16, 2:8.2.3995-1ubuntu2.10
vim (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.16, 2:8.2.3995-1ubuntu2.10
vim-gtk (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.16, 2:8.2.3995-1ubuntu2.10
vim-tiny (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.16, 2:8.2.3995-1ubuntu2.10
xxd (Ubuntu package) - addressed in versions Ubuntu Pro, 2:8.1.2269-1ubuntu5.16, 2:8.2.3995-1ubuntu2.10
vim-gtk3 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.16, 2:8.2.3995-1ubuntu2.10
vim-nox (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:8.1.2269-1ubuntu5.16, 2:8.2.3995-1ubuntu2.10
VMware Tanzu Operations Manager - addressed in versions 2.10.61, 3.0.15
vim-filesystem - update to 8.2-46
vim - update to 8.2-46
vim-debugsource - update to 8.2-46
vim-enhanced - update to 8.2-46
vim-X11 - update to 8.2-46
vim-debuginfo - update to 8.2-46
vim-common - update to 8.2-46
vim-minimal - update to 8.2-46
vim - addressed in versions 9.0.049-1.fc35, 9.0.049-1.fc36
app-editors/vim-core - addressed in versions 9.0.0060, 9.0.1157
app-editors/vim - addressed in versions 9.0.0060, 9.0.1157
app-editors/gvim - addressed in versions 9.0.0060, 9.0.1157
vim - addressed in versions 9.0.475-1.1, 9.0.1160-1.1

External References

Related Security Bulletins