Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.
References
Link | Resource |
---|---|
https://huntr.dev/bounties/20ece512-c600-45ac-8a84-d0931e05541f | Exploit Issue Tracking Patch Third Party Advisory |
https://github.com/vim/vim/commit/cc762a48d42b579fb7bdec2c614636b830342dd5 | Patch Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AZ3JMSUCR6Y7626RDWQ2HNSUFIQOJ33G/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/V6ZNKVN4GICORTVFKVCM4MSOXCYWNHUC/ | Mailing List Third Party Advisory |
Information
Published : 2022-11-25 06:15
Updated : 2023-01-10 11:51
NVD link : CVE-2022-4141
Mitre link : CVE-2022-4141
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
vim
- vim
fedoraproject
- fedora