ALT-PU-2020-2198-1
Closed vulnerabilities
Published: 2022-01-25
BDU:2022-00983
Уязвимость текстового редактора vim, связанная с доступом к ячейки памяти, предшествующий началу буфера, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Severity: HIGH (7.8)
Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity: MEDIUM (6.8)
Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C
References:
Published: 2022-01-14
BDU:2022-01025
Уязвимость функции NameBuff текстового редактора vim, позволяющая нарушителю вызвать переполнение буфера
Severity: MEDIUM (6.6)
Vector: AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Severity: MEDIUM (5.9)
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:C
References:
Published: 2022-01-14
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2022-0213
vim is vulnerable to Heap-based Buffer Overflow
Severity: MEDIUM (6.8)
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
Severity: MEDIUM (6.6)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
References:
- http://www.openwall.com/lists/oss-security/2022/01/15/1
- https://github.com/vim/vim/commit/de05bb25733c3319e18dca44e9b59c6ee389eb26
- https://huntr.dev/bounties/f3afe1a5-e6f8-4579-b68a-6e5c7e39afed
- https://lists.debian.org/debian-lts-announce/2022/03/msg00018.html
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://security.gentoo.org/glsa/202208-32
- http://www.openwall.com/lists/oss-security/2022/01/15/1
- https://github.com/vim/vim/commit/de05bb25733c3319e18dca44e9b59c6ee389eb26
- https://huntr.dev/bounties/f3afe1a5-e6f8-4579-b68a-6e5c7e39afed
- https://lists.debian.org/debian-lts-announce/2022/03/msg00018.html
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://security.gentoo.org/glsa/202208-32
Published: 2022-01-25
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2022-0351
Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2.
Severity: MEDIUM (4.6)
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P
Severity: HIGH (7.8)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References:
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- http://seclists.org/fulldisclosure/2022/Oct/43
- https://github.com/vim/vim/commit/fe6fb267e6ee5c5da2f41889e4e0e0ac5bf4b89d
- https://huntr.dev/bounties/8b36db58-b65c-4298-be7f-40b9e37fd161
- https://lists.debian.org/debian-lts-announce/2022/05/msg00022.html
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://security.gentoo.org/glsa/202208-32
- https://support.apple.com/kb/HT213444
- https://support.apple.com/kb/HT213488
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- http://seclists.org/fulldisclosure/2022/Oct/43
- https://github.com/vim/vim/commit/fe6fb267e6ee5c5da2f41889e4e0e0ac5bf4b89d
- https://huntr.dev/bounties/8b36db58-b65c-4298-be7f-40b9e37fd161
- https://lists.debian.org/debian-lts-announce/2022/05/msg00022.html
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://security.gentoo.org/glsa/202208-32
- https://support.apple.com/kb/HT213444
- https://support.apple.com/kb/HT213488
Closed bugs
собрать с поддержкой python3