CLSA-2025-1761845210

    Dashboard / Vulnerabilities / CLSA-2025-1761845210

    CLSA-2025-1761845210

    Published: 30 Oct 2025Last Modified: 4 Jun 2026

    Summary: Fix CVE(s): CVE-2022-1733, CVE-2022-1796, CVE-2022-1886, CVE-2022-3016

    Details: * SECURITY UPDATE: Heap-based Buffer Overflow - debian/patches/CVE-2022-1733.patch: Check for NUL to prevent reading past end of the line when C-indenting - CVE-2022-1733 * SECURITY UPDATE: Use After Free - debian/patches/CVE-2022-1796.patch: Fix accessing freed memory when line is flushed by making a copy of the search pattern - CVE-2022-1796 * SECURITY UPDATE: Heap-based Buffer Overflow - debian/patches/CVE-2022-1886.patch: Check the length is more than zero to fix access before start of text with a put command - CVE-2022-1886 * SECURITY UPDATE: Use After Free - debian/patches/CVE-2022-3016.patch: Return QF_ABORT when location list changed in autocmd - CVE-2022-3016

    Affected packages

    Package

    Name: vim

    Purl: pkg:deb/tuxcare/vim?distro=debian-10

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2:8.1.0875-5+deb10u6+tuxcare.els5

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CLSA-2025-1761845210 | CVE-DB