CLSA-2022-1658172267

    Dashboard / Vulnerabilities / CLSA-2022-1658172267

    CLSA-2022-1658172267

    Published: 18 Jul 2022Last Modified: 4 Jun 2026

    Summary: Fix CVE(s): CVE-2022-2206, CVE-2022-2257, CVE-2022-2286, CVE-2022-2285, CVE-2022-2284, CVE-2022-2287, CVE-2022-2264

    Details: * SECURITY UPDATE: Out-of-bound read in function msg_outtrans_attr - debian/patches/CVE-2022-2206.patch: Adjust cmdline_row and msg_row to the value of Rows. - CVE-2022-2206 * SECURITY UPDATE: Heap-based buffer overflow in function utfc_ptr2len - debian/patches/CVE-2022-2284.patch: Stop Visual mode when closing a window. - CVE-2022-2284 * SECURITY UPDATE: Integer overflow in function del_typebuf - debian/patches/CVE-2022-2285.patch: Put a NUL after the typeahead - CVE-2022-2285 * SECURITY UPDATE: Out-of-bounds read in function ins_bytes - debian/patches/CVE-2022-2286.patch: Check the length of the string - CVE-2022-2286 * SECURITY UPDATE: Out-of-bound read data in function suggest_trie_walk() abusing array byts - debian/patches/CVE-2022-2287.patch: Disallow adding a word with control characters or a trailing slash. - CVE-2022-2287 * SECURITY UPDATE: Heap-based buffer overflow in function inc on put command - debian/patches/CVE-2022-2264.patch: Adjust the end mark position. - CVE-2022-2264 * SECURITY UPDATE: Out-of-bound read in function msg_outtrans_special - debian/patches/CVE-2022-2257.patch: check for NUL in str2special - CVE-2022-2257

    Affected packages

    Package

    Name: vim

    Purl: pkg:deb/tuxcare/vim?distro=ubuntu-16.04

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3:7.4.1689-3ubuntu1.5+tuxcare.els23

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CLSA-2022-1658172267 | CVE-DB