Related Vulnerabilities: CVE-2022-2522  

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0060.

Description

The MITRE CVE dictionary describes this issue as:

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0060.

Statement

Red Hat Product Security has rated this issue as having a Low security impact because the "victim" has to run an untrusted file IN SCRIPT MODE. Someone who is running untrusted files in script mode is equivalent to someone just taking a random python script and running it.

Red Hat Product Security has rated this issue as having a Low security impact because the "victim" has to run an untrusted file IN SCRIPT MODE. Someone who is running untrusted files in script mode is equivalent to someone just taking a random python script and running it.

Additional Information

  • Bugzilla 2112299: CVE-2022-2522 vim: heap-based buffer overflow in ins_compl_infercase_gettext() at src/insexpand.c
  • CWE-122: Heap-based Buffer Overflow
  • FAQ: Frequently asked questions about CVE-2022-2522