CVE-2022-1154Use After Free in VIM

CWE-416Use After Free14 documents9 sources
Severity
7.8HIGHNVD
EPSS
0.6%
top 30.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 30
Latest updateOct 15

Description

Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

NVDvim/vim< 8.2.4646
CVEListV5vim/vim_vimunspecified8.2.4646
Debianvim/vim< 2:8.2.4659-1+2

Also affects: Debian Linux 10.0, 9.0, Fedora 34, 35

Patches

🔴Vulnerability Details

5
OSV
vim regression2022-09-19
OSV
vim vulnerabilities2022-09-15
GHSA
GHSA-wm74-7g5x-vq4x: Use after free in utf_ptr2char in GitHub repository vim/vim prior to 82022-03-31
OSV
CVE-2022-1154: Use after free in utf_ptr2char in GitHub repository vim/vim prior to 82022-03-30
CVEList
Use after free in utf_ptr2char in vim/vim2022-03-30

📋Vendor Advisories

8
Oracle
Oracle Oracle Communications Risk Matrix: DBTier (vim) — CVE-2022-11542022-10-15
Ubuntu
Vim regression2022-09-19
Ubuntu
Vim vulnerabilities2022-09-15
Oracle
Oracle Oracle Communications Risk Matrix: NEF (vim) — CVE-2022-11542022-07-15
Ubuntu
Vim vulnerabilities2022-05-23
CVE-2022-1154 — Use After Free in VIM VIM | cvebase