CVE-2022-3520
Heap-based Buffer Overflow in vim/vim
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.
Desbordamiento de búfer de almacenamiento dinámico en el repositorio de GitHub vim/vim anterior a 9.0.0765.
It was discovered that Vim incorrectly handled memory when opening certain files. If an attacker could trick a user into opening a specially crafted file, it could cause Vim to crash, or possibly execute arbitrary code. This issue only affected Ubuntu 22.04 LTS. It was discovered that Vim incorrectly handled memory when opening certain files. If an attacker could trick a user into opening a specially crafted file, it could cause Vim to crash, or possibly execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-10-15 CVE Reserved
- 2022-12-02 CVE Published
- 2024-11-15 CVE Updated
- 2024-11-15 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-122: Heap-based Buffer Overflow
- CWE-787: Out-of-bounds Write
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://huntr.dev/bounties/c1db3b70-f4fe-481f-8a24-0b1449c94246 | 2024-11-15 |
URL | Date | SRC |
---|---|---|
https://github.com/vim/vim/commit/36343ae0fb7247e060abfd35fb8e4337b33abb4b | 2023-05-03 |
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/202305-16 | 2023-05-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vim Search vendor "Vim" | Vim Search vendor "Vim" for product "Vim" | < 9.0.0765 Search vendor "Vim" for product "Vim" and version " < 9.0.0765" | - |
Affected
|