SUSE-SU-2022:3229-1

    Dashboard / Vulnerabilities / SUSE-SU-2022:3229-1

    SUSE-SU-2022:3229-1

    Published: 9 Sept 2022Last Modified: 4 Feb 2026

    Summary: Security update for vim

    Details: This update for vim fixes the following issues: Updated to version 9.0 with patch level 0313: - CVE-2022-2183: Fixed out-of-bounds read through get_lisp_indent() (bsc#1200902). - CVE-2022-2182: Fixed heap-based buffer overflow through parse_cmd_address() (bsc#1200903). - CVE-2022-2175: Fixed buffer over-read through cmdline_insert_reg() (bsc#1200904). - CVE-2022-2304: Fixed stack buffer overflow in spell_dump_compl() (bsc#1201249). - CVE-2022-2343: Fixed heap-based buffer overflow in GitHub repository vim prior to 9.0.0044 (bsc#1201356). - CVE-2022-2344: Fixed another heap-based buffer overflow vim prior to 9.0.0045 (bsc#1201359). - CVE-2022-2345: Fixed use after free in GitHub repository vim prior to 9.0.0046. (bsc#1201363). - CVE-2022-2819: Fixed heap-based Buffer Overflow in compile_lock_unlock() (bsc#1202414). - CVE-2022-2874: Fixed NULL Pointer Dereference in generate_loadvar() (bsc#1202552). - CVE-2022-1968: Fixed use after free in utf_ptr2char (bsc#1200270). - CVE-2022-2124: Fixed out of bounds read in current_quote() (bsc#1200697). - CVE-2022-2125: Fixed out of bounds read in get_lisp_indent() (bsc#1200698). - CVE-2022-2126: Fixed out of bounds read in suggest_trie_walk() (bsc#1200700). - CVE-2022-2129: Fixed out of bounds write in vim_regsub_both() (bsc#1200701). - CVE-2022-1720: Fixed out of bounds read in grab_file_name() (bsc#1200732). - CVE-2022-2264: Fixed out of bounds read in inc() (bsc#1201132). - CVE-2022-2284: Fixed out of bounds read in utfc_ptr2len() (bsc#1201133). - CVE-2022-2285: Fixed negative size passed to memmove() due to integer overflow (bsc#1201134). - CVE-2022-2286: Fixed out of bounds read in ins_bytes() (bsc#1201135). - CVE-2022-2287: Fixed out of bounds read in suggest_trie_walk() (bsc#1201136). - CVE-2022-2231: Fixed null pointer dereference skipwhite() (bsc#1201150). - CVE-2022-2210: Fixed out of bounds read in ml_append_int() (bsc#1201151). - CVE-2022-2208: Fixed null pointer dereference in diff_check() (bsc#1201152). - CVE-2022-2207: Fixed out of bounds read in ins_bs() (bsc#1201153). - CVE-2022-2257: Fixed out of bounds read in msg_outtrans_special() (bsc#1201154). - CVE-2022-2206: Fixed out of bounds read in msg_outtrans_attr() (bsc#1201155). - CVE-2022-2522: Fixed out of bounds read via nested autocommand (bsc#1201863). - CVE-2022-2571: Fixed heap-based buffer overflow related to ins_comp_get_next_word_or_line() (bsc#1202046). - CVE-2022-2580: Fixed heap-based buffer overflow related to eval_string() (bsc#1202049). - CVE-2022-2581: Fixed out-of-bounds read related to cstrchr() (bsc#1202050). - CVE-2022-2598: Fixed undefined behavior for Input to API related to diff_mark_adjust_tp() and ex_diffgetput() (bsc#1202051). - CVE-2022-2817: Fixed use after gree in f_assert_fails() (bsc#1202420). - CVE-2022-2816: Fixed out-of-bounds Read in check_vim9_unlet() (bsc#1202421). - CVE-2022-2862: Fixed use-after-free in compile_nested_function() (bsc#1202511). - CVE-2022-2849: Fixed invalid memory access related to mb_ptr2len() (bsc#1202512). - CVE-2022-2845: Fixed buffer Over-read related to display_dollar() (bsc#1202515). - CVE-2022-2889: Fixed use-after-free in find_var_also_in_script() in evalvars.c (bsc#1202599). - CVE-2022-2923: Fixed NULL pointer dereference in GitHub repository vim/vim prior to 9.0.0240 (bsc#1202687). - CVE-2022-2946: Fixed use after free in function vim_vsnprintf_typval (bsc#1202689). - CVE-2022-3016: Fixed use after free in vim prior to 9.0.0285 (bsc#1202862). Bugfixes: - Fixing vim error on startup (bsc#1200884). - Fixing vim SUSE Linux Enterprise Server 15 SP4 Basesystem plugin-tlib issue (bsc#1201620).

    References: https://www.suse.com/support/update/announcement/2022/suse-su-20223229-1/, https://bugzilla.suse.com/1200270, https://bugzilla.suse.com/1200697, https://bugzilla.suse.com/1200698, https://bugzilla.suse.com/1200700, https://bugzilla.suse.com/1200701, https://bugzilla.suse.com/1200732, https://bugzilla.suse.com/1200884, https://bugzilla.suse.com/1200902, https://bugzilla.suse.com/1200903, https://bugzilla.suse.com/1200904, https://bugzilla.suse.com/1201132, https://bugzilla.suse.com/1201133, https://bugzilla.suse.com/1201134, https://bugzilla.suse.com/1201135, https://bugzilla.suse.com/1201136, https://bugzilla.suse.com/1201150, https://bugzilla.suse.com/1201151, https://bugzilla.suse.com/1201152, https://bugzilla.suse.com/1201153, https://bugzilla.suse.com/1201154, https://bugzilla.suse.com/1201155, https://bugzilla.suse.com/1201249, https://bugzilla.suse.com/1201356, https://bugzilla.suse.com/1201359, https://bugzilla.suse.com/1201363, https://bugzilla.suse.com/1201620, https://bugzilla.suse.com/1201863, https://bugzilla.suse.com/1202046, https://bugzilla.suse.com/1202049, https://bugzilla.suse.com/1202050, https://bugzilla.suse.com/1202051, https://bugzilla.suse.com/1202414, https://bugzilla.suse.com/1202420, https://bugzilla.suse.com/1202421, https://bugzilla.suse.com/1202511, https://bugzilla.suse.com/1202512, https://bugzilla.suse.com/1202515, https://bugzilla.suse.com/1202552, https://bugzilla.suse.com/1202599, https://bugzilla.suse.com/1202687, https://bugzilla.suse.com/1202689, https://bugzilla.suse.com/1202862, https://www.suse.com/security/cve/CVE-2022-1720, https://www.suse.com/security/cve/CVE-2022-1968, https://www.suse.com/security/cve/CVE-2022-2124, https://www.suse.com/security/cve/CVE-2022-2125, https://www.suse.com/security/cve/CVE-2022-2126, https://www.suse.com/security/cve/CVE-2022-2129, https://www.suse.com/security/cve/CVE-2022-2175, https://www.suse.com/security/cve/CVE-2022-2182, https://www.suse.com/security/cve/CVE-2022-2183, https://www.suse.com/security/cve/CVE-2022-2206, https://www.suse.com/security/cve/CVE-2022-2207, https://www.suse.com/security/cve/CVE-2022-2208, https://www.suse.com/security/cve/CVE-2022-2210, https://www.suse.com/security/cve/CVE-2022-2231, https://www.suse.com/security/cve/CVE-2022-2257, https://www.suse.com/security/cve/CVE-2022-2264, https://www.suse.com/security/cve/CVE-2022-2284, https://www.suse.com/security/cve/CVE-2022-2285, https://www.suse.com/security/cve/CVE-2022-2286, https://www.suse.com/security/cve/CVE-2022-2287, https://www.suse.com/security/cve/CVE-2022-2304, https://www.suse.com/security/cve/CVE-2022-2343, https://www.suse.com/security/cve/CVE-2022-2344, https://www.suse.com/security/cve/CVE-2022-2345, https://www.suse.com/security/cve/CVE-2022-2522, https://www.suse.com/security/cve/CVE-2022-2571, https://www.suse.com/security/cve/CVE-2022-2580, https://www.suse.com/security/cve/CVE-2022-2581, https://www.suse.com/security/cve/CVE-2022-2598, https://www.suse.com/security/cve/CVE-2022-2816, https://www.suse.com/security/cve/CVE-2022-2817, https://www.suse.com/security/cve/CVE-2022-2819, https://www.suse.com/security/cve/CVE-2022-2845, https://www.suse.com/security/cve/CVE-2022-2849, https://www.suse.com/security/cve/CVE-2022-2862, https://www.suse.com/security/cve/CVE-2022-2874, https://www.suse.com/security/cve/CVE-2022-2889, https://www.suse.com/security/cve/CVE-2022-2923, https://www.suse.com/security/cve/CVE-2022-2946, https://www.suse.com/security/cve/CVE-2022-3016

    Affected packages

    Package

    Name: vim

    Purl: pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -9.0.0313-150000.5.25.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2022:3229-1 | CVE-DB