CVE-2022-47024
published 2023-01-20CVE-2022-47024: A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru 9.0.0339 allows attackers to cause…
PriorityP431high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.5th percentile
A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru 9.0.0339 allows attackers to cause denial of service or other unspecified impacts.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | vim | < vim 2:9.0.0626-1 (bookworm) | vim 2:9.0.0626-1 (bookworm) |
| vim | vim | >= 0 < 2:9.0.0626-1 | 2:9.0.0626-1 |
| vim | vim | >= 0 < 2:9.0.0626-1 | 2:9.0.0626-1 |
| vim | vim | >= 0 < 2:9.0.0626-1 | 2:9.0.0626-1 |
| vim | vim | >= 0 < 2:8.0.1453-1ubuntu1.11 | 2:8.0.1453-1ubuntu1.11 |
| vim | vim | >= 0 < 2:8.1.2269-1ubuntu5.12 | 2:8.1.2269-1ubuntu5.12 |
| vim | vim | >= 0 < 2:8.2.3995-1ubuntu2.4 | 2:8.2.3995-1ubuntu2.4 |
| vim | vim | >= 0 < 2:7.4.052-1ubuntu3.1+esm7 | 2:7.4.052-1ubuntu3.1+esm7 |
| vim | vim | >= 0 < 2:7.4.1689-3ubuntu1.5+esm17 | 2:7.4.1689-3ubuntu1.5+esm17 |
| vim | vim | 8.1.2269 – 9.0.0339 | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Vim vulnerabilities
vendor_ubuntu·2023-03-20·CVSS 7.8
CVE-2023-0054 [HIGH] Vim vulnerabilities
Title: Vim vulnerabilities
Summary: Several security issues were fixed in Vim.
It was discovered that Vim was not properly performing memory management
operations. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This issue only affected Ubuntu 18.04
LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 22.10. (CVE-2022-47024,
CVE-2023-0049, CVE-2023-0054, CVE-2023-0288, CVE-2023-0433)
It was discovered that Vim was not properly performing memory management
operations. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This issue only affected Ubuntu 22.04
LTS, and Ubuntu 22.10. (CVE-2023-0051)
It was discovered that Vim was not properly performing memory management
operations. An attacker cou
Ubuntu
Vim vulnerabilities
vendor_ubuntu·2023-01-31·CVSS 7.8
CVE-2022-47024 [HIGH] Vim vulnerabilities
Title: Vim vulnerabilities
Summary: Several security issues were fixed in Vim.
It was discovered that Vim was not properly performing memory management
operations. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. (CVE-2022-47024, CVE-2023-0049,
CVE-2023-0054, CVE-2023-0288, CVE-2023-0433)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
vim: no check if the return value of XChangeGC() is NULL
vendor_redhat·2023-01-20·CVSS 7.8
CVE-2022-47024 [HIGH] CWE-252 vim: no check if the return value of XChangeGC() is NULL
vim: no check if the return value of XChangeGC() is NULL
A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru 9.0.0339 allows attackers to cause denial of service or other unspecified impacts.
A NULL pointer dereference issue was found in Vim's gui_x11_create_blank_mouse function in gui_x11.c. This flaw allows attackers to cause a denial of service and other unspecified impacts.
Package: vim (Red Hat Enterprise Linux 6) - Not affected
Package: vim (Red Hat Enterprise Linux 7) - Not affected
Package: vim (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2022-47024: vim - A null pointer dereference issue was discovered in function gui_x11_create_blank...
vendor_debian·2022·CVSS 7.8
CVE-2022-47024 [HIGH] CVE-2022-47024: vim - A null pointer dereference issue was discovered in function gui_x11_create_blank...
A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru 9.0.0339 allows attackers to cause denial of service or other unspecified impacts.
Scope: local
bookworm: resolved (fixed in 2:9.0.0626-1)
bullseye: open
forky: resolved (fixed in 2:9.0.0626-1)
sid: resolved (fixed in 2:9.0.0626-1)
trixie: resolved (fixed in 2:9.0.0626-1)
OSV
vim vulnerabilities
osv·2023-03-20·CVSS 7.8
CVE-2022-47024 [HIGH] vim vulnerabilities
vim vulnerabilities
It was discovered that Vim was not properly performing memory management
operations. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This issue only affected Ubuntu 18.04
LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 22.10. (CVE-2022-47024,
CVE-2023-0049, CVE-2023-0054, CVE-2023-0288, CVE-2023-0433)
It was discovered that Vim was not properly performing memory management
operations. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This issue only affected Ubuntu 22.04
LTS, and Ubuntu 22.10. (CVE-2023-0051)
It was discovered that Vim was not properly performing memory management
operations. An attacker could possibly use this issue to cause a denial
of service or e
GHSA
GHSA-5jpw-hxh6-542f: A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11
ghsa_unreviewed·2023-01-20
CVE-2022-47024 [HIGH] CWE-476 GHSA-5jpw-hxh6-542f: A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11
A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru 9.0.0339 allows attackers to cause denial of service or other unspecified impacts.
OSV
CVE-2022-47024: A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11
osv·2023-01-20·CVSS 7.8
CVE-2022-47024 [HIGH] CVE-2022-47024: A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11
A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru 9.0.0339 allows attackers to cause denial of service or other unspecified impacts.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/vim/vim/commit/a63ad78ed31e36dbdf3a9cd28071dcdbefce7d19https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4EX6N2DB75A73MQGVW3CS4VTNPAYVM2M/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PZWIJBSQX53P7DHV77KRXJIXA4GH7XHC/https://security.gentoo.org/glsa/202305-16https://github.com/vim/vim/commit/a63ad78ed31e36dbdf3a9cd28071dcdbefce7d19https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4EX6N2DB75A73MQGVW3CS4VTNPAYVM2M/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PZWIJBSQX53P7DHV77KRXJIXA4GH7XHC/https://security.gentoo.org/glsa/202305-16
2023-01-20
Published