cbcvebase.
CVE-2022-3705
published 2022-10-26

CVE-2022-3705: A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer of the file quickfix.c of the component…

PriorityP341high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
1.20%
64.6th percentile
A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer of the file quickfix.c of the component autocmd Handler. The manipulation leads to use after free. The attack may be launched remotely. Upgrading to version 9.0.0805 is able to address this issue. The name of the patch is d0fab10ed2a86698937e3c3fed2f10bd9bb5e731. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-212324.

Affected

15 ranges
VendorProductVersion rangeFixed in
applemacos_ventura
debiandebian_linux
debianvim< vim 2:9.0.0813-1 (bookworm)vim 2:9.0.0813-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_vim_9.0.0805-1_on_cbl_mariner_2.0
msrccm1_vim_9.0.0805-1_on_cbl_mariner_1.0
vimvim< 9.0.08059.0.0805
vimvim>= 0 < 2:9.0.0813-12:9.0.0813-1
vimvim>= 0 < 2:9.0.0813-12:9.0.0813-1
vimvim>= 0 < 2:9.0.0813-12:9.0.0813-1
vimvim>= 0 < 2:8.1.2269-1ubuntu5.182:8.1.2269-1ubuntu5.18
vimvim>= 0 < 2:8.2.3995-1ubuntu2.122:8.2.3995-1ubuntu2.12
vimvim>= 0 < 2:7.4.052-1ubuntu3.1+esm132:7.4.052-1ubuntu3.1+esm13
vimvim>= 0 < 2:8.0.1453-1ubuntu1.13+esm52:8.0.1453-1ubuntu1.13+esm5

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc7.5HIGH
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.