UBUNTU-CVE-2022-1621
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-1621
UBUNTU-CVE-2022-1621
Summary:
Details: Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
References: https://ubuntu.com/security/CVE-2022-1621, https://huntr.dev/bounties/520ce714-bfd2-4646-9458-f52cd22bb2fb, https://github.com/vim/vim/commit/7c824682d2028432ee082703ef0ab399867a089b, https://github.com/vim/vim/commit/7c824682d2028432ee082703ef0ab399867a089b, https://ubuntu.com/security/notices/USN-5460-1, https://ubuntu.com/security/notices/USN-5613-1, https://www.cve.org/CVERecord?id=CVE-2022-1621, https://ubuntu.com/security/notices/USN-5613-2
Affected packages
Package
Name: vim
Purl: pkg:deb/ubuntu/vim@2:7.4.052-1ubuntu3.1+esm5?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
