CVE-2022-0158
Published: 10 January 2022
vim is vulnerable to Heap-based Buffer Overflow
Priority
CVSS 3 base score: 3.3
Status
Package | Release | Status |
---|---|---|
vim Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(code not present)
|
focal |
Not vulnerable
(code not present)
|
|
hirsute |
Ignored
(reached end-of-life)
|
|
impish |
Needed
|
|
jammy |
Needed
|
|
trusty |
Not vulnerable
(code not present)
|
|
upstream |
Released
(v8.2.4049)
|
|
xenial |
Not vulnerable
(code not present)
|
Notes
Author | Note |
---|---|
rayveldkamp | affected function is located in src/vim9compile.c for these releases |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0158
- https://huntr.dev/bounties/ac5d7005-07c6-4a0a-b251-ba9cdbf6738b/
- https://github.com/vim/vim/commit/5f25c3855071bd7e26255c68bf458b1b5cf92f39 (v8.2.4049)
- https://huntr.dev/bounties/ac5d7005-07c6-4a0a-b251-ba9cdbf6738b
- NVD
- Launchpad
- Debian