CLSA-2022-1657813374

    Dashboard / Vulnerabilities / CLSA-2022-1657813374

    CLSA-2022-1657813374

    Published: 14 Jul 2022Last Modified: 4 Jun 2026

    Summary: Fix CVE(s): CVE-2022-2182, CVE-2022-2183, CVE-2022-2210, CVE-2022-2207

    Details: * SECURITY UPDATE: Heap-based buffer overflow in function utf_ptr2char - debian/patches/CVE-2022-2182.patch: When on line zero check the column is valid for line one in do_one_cmd function - CVE-2022-2182 * SECURITY UPDATE: Out-of-bounds read in function get_lisp_indent - debian/patches/CVE-2022-2183.patch: Add check to avoid going over the NUL at the end of the line in get_lisp_indent function - CVE-2022-2183 * SECURITY UPDATE: Heap-based buffer overflow in function ins_bs - debian/patches/CVE-2022-2207.patch: Check the cursor column is more than zero in ins_bs function - CVE-2022-2207 * SECURITY UPDATE: Out-of-bound write in function ml_append_int - debian/patches/CVE-2022-2210.patch: Use zero offset when change removes all lines in a diff block in diff_mark_adjust_tp function - CVE-2022-2210

    Affected packages

    Package

    Name: vim

    Purl: pkg:deb/tuxcare/vim?distro=ubuntu-16.04

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3:7.4.1689-3ubuntu1.5+tuxcare.els22

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CLSA-2022-1657813374 | CVE-DB