CVE-2022-1674NULL Pointer Dereference in VIM

Severity
5.5MEDIUMNVD
OSV7.8
EPSS
0.1%
top 68.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 12
Latest updateApr 4

Description

NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in GitHub repository vim/vim prior to 8.2.4938. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 allows attackers to cause a denial of service (application crash) via a crafted input.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDvim/vim< 8.2.4938
CVEListV5vim/vim_vimunspecified8.2.4938
NVDapple/macos< 13.0
Debianvim/vim< 2:9.0.0135-1+2
Ubuntuvim/vim< 2:8.0.1453-1ubuntu1.12+4

Also affects: Fedora 34, 35, 36

Patches

🔴Vulnerability Details

5
OSV
vim vulnerabilities2023-04-04
OSV
vim vulnerabilities2022-11-14
GHSA
GHSA-rx8p-hg5g-g9hg: NULL Pointer Dereference in function vim_regexec_string at regexp2022-05-13
OSV
CVE-2022-1674: NULL Pointer Dereference in function vim_regexec_string at regexp2022-05-12
CVEList
NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in vim/vim2022-05-12

📋Vendor Advisories

6
Ubuntu
Vim vulnerabilities2023-04-04
Ubuntu
Vim vulnerabilities2022-11-14
Apple
CVE-2022-1674: macOS Ventura 132022-10-24
Red Hat
vim: NULL pointer dereference in vim_regexec_string() of regexp.c2022-05-12
Microsoft
NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in vim/vim2022-05-10

🕵️Threat Intelligence

2
Talos
Vulnerability Spotlight: WellinTech ICS platform vulnerable to information disclosure, buffer overflow vulnerabilities2023-03-21
Talos
Vulnerability Spotlight: WellinTech ICS platform vulnerable to information disclosure, buffer overflow vulnerabilities2023-03-21
CVE-2022-1674 — NULL Pointer Dereference in VIM VIM | cvebase