CVE-2022-4141Heap-based Buffer Overflow in VIM

Severity
7.8HIGHNVD
EPSS
0.0%
top 88.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 25

Description

Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5vim/vim_vimunspecified9.0.0947
Debianvim/vim< 2:8.2.2434-3+deb11u2+3
NVDvim/vim9.0.0946

Also affects: Fedora 36, 37

Patches

🔴Vulnerability Details

3
OSV
CVE-2022-4141: Heap based buffer overflow in vim/vim 92022-11-25
GHSA
GHSA-w2q9-j8v8-2gf2: The target's backtrace indicates that libc has detected a heap error or that the target was executing a heap function when it stopped2022-11-25
CVEList
Heap-based Buffer Overflow in vim/vim2022-11-25

📋Vendor Advisories

3
Red Hat
vim: invalid memory access in substitute with function2022-11-25
Microsoft
Heap-based Buffer Overflow in vim/vim2022-11-08
Debian
CVE-2022-4141: vim - Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker...2022
CVE-2022-4141 — Heap-based Buffer Overflow in VIM VIM | cvebase