Related Vulnerabilities: CVE-2022-0685  

A flaw was found in vim. The vulnerability occurs due to a crash when using a special multi-byte character and leads to an out-of-range vulnerability. This flaw allows an attacker to input a specially crafted file, leading to a crash or code execution.

Description

A flaw was found in vim. The vulnerability occurs due to a crash when using a special multi-byte character and leads to an out-of-range vulnerability. This flaw allows an attacker to input a specially crafted file, leading to a crash or code execution.

Mitigation

Untrusted vim scripts with -s [scriptin] are not recommended to run.

Additional Information

  • Bugzilla 2057820: CVE-2022-0685 : vim: Use of Out-of-range Pointer Offset in vim
  • CWE-125: Out-of-bounds Read
  • FAQ: Frequently asked questions about CVE-2022-0685