CVE-2024-22667
published 2024-02-05CVE-2024-22667: Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the…
PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.56%
43.1th percentile
Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | vim | < vim 2:9.0.1378-2+deb12u1 (bookworm) | vim 2:9.0.1378-2+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_vim_9.0.2121-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_vim_9.0.2121-5_on_cbl_mariner_2.0 | — | — |
| vim | vim | < 9.0.2142 | 9.0.2142 |
| vim | vim | >= 0 < 2:8.2.2434-3+deb11u2 | 2:8.2.2434-3+deb11u2 |
| vim | vim | >= 0 < 2:9.0.1378-2+deb12u1 | 2:9.0.1378-2+deb12u1 |
| vim | vim | >= 0 < 2:9.0.2189-1 | 2:9.0.2189-1 |
| vim | vim | >= 0 < 2:9.0.2189-1 | 2:9.0.2189-1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Vim vulnerability
vendor_ubuntu·2024-03-18
CVE-2024-22667 Vim vulnerability
Title: Vim vulnerability
Summary: Vim could be made to crash if it opened a specially crafted file.
Zhen Zhou discovered that Vim did not properly manage memory. An
attacker could possibly use this issue to cause a denial of service
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions.
vendor_msrc·2024-02-13·CVSS 7.8
CVE-2024-22667 [HIGH] CWE-787 Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions.
Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect t
Red Hat
vim: Stack buffer over flow in did_set_langmap function in map.c
vendor_redhat·2024-02-05·CVSS 7.8
CVE-2024-22667 [HIGH] CWE-121 vim: Stack buffer over flow in did_set_langmap function in map.c
vim: Stack buffer over flow in did_set_langmap function in map.c
Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions.
A stack-based buffer overflow flaw was found in Vim. The did_set_langmap function in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions. That buffer can be overflown, possibly leading to memory corruption and escalation of privileges.
Statement: Escalation of privilege may only be attained if the Vim binary can be run with non-default higher privileges, which is a rare scenario, for example, setuid which makes this vulnerability only to be exploited via high privileges making the severity as
Debian
CVE-2024-22667: vim - Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in...
vendor_debian·2024·CVSS 7.8
CVE-2024-22667 [HIGH] CVE-2024-22667: vim - Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in...
Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions.
Scope: local
bookworm: resolved (fixed in 2:9.0.1378-2+deb12u1)
bullseye: resolved (fixed in 2:8.2.2434-3+deb11u2)
forky: resolved (fixed in 2:9.0.2189-1)
sid: resolved (fixed in 2:9.0.2189-1)
trixie: resolved (fixed in 2:9.0.2189-1)
OSV
CVE-2024-22667: Vim before 9
osv·2024-02-05·CVSS 7.8
CVE-2024-22667 [HIGH] CVE-2024-22667: Vim before 9
Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions.
GHSA
GHSA-jhwv-44fv-jwp5: Vim before 9
ghsa_unreviewed·2024-02-05
CVE-2024-22667 [HIGH] CWE-787 GHSA-jhwv-44fv-jwp5: Vim before 9
Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gist.githubusercontent.com/henices/2467e7f22dcc2aa97a2453e197b55a0c/raw/7b54bccc9a129c604fb139266f4497ab7aaa94c7/gistfile1.txthttps://github.com/vim/vim/commit/b39b240c386a5a29241415541f1c99e2e6b8ce47https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UI44Y4LJLG34D4HNB6NTPLUPZREHAEL7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UIQLVUSYHDN3644K6EFDI7PRZOTIKXM3/https://security.netapp.com/advisory/ntap-20240223-0008/https://gist.githubusercontent.com/henices/2467e7f22dcc2aa97a2453e197b55a0c/raw/7b54bccc9a129c604fb139266f4497ab7aaa94c7/gistfile1.txthttps://github.com/vim/vim/commit/b39b240c386a5a29241415541f1c99e2e6b8ce47https://lists.debian.org/debian-lts-announce/2025/03/msg00023.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UI44Y4LJLG34D4HNB6NTPLUPZREHAEL7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UIQLVUSYHDN3644K6EFDI7PRZOTIKXM3/https://lists.fedoraproject.org/archives/list/[email protected]/message/UI44Y4LJLG34D4HNB6NTPLUPZREHAEL7/https://lists.fedoraproject.org/archives/list/[email protected]/message/UIQLVUSYHDN3644K6EFDI7PRZOTIKXM3/https://security.netapp.com/advisory/ntap-20240223-0008/
2024-02-05
Published