Bugzilla – Bug 1197225
VUL-0: CVE-2022-0943: vim: Heap-based Buffer Overflow occurs in vim
Last modified: 2022-03-17 13:15:01 UTC
Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2. https://github.com/vim/vim/commit/5c68617d395f9d7b824f68475b24ce3e38d653a3 References: https://bugzilla.redhat.com/show_bug.cgi?id=2064064 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-0943 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0943 https://github.com/vim/vim/commit/5c68617d395f9d7b824f68475b24ce3e38d653a3 https://huntr.dev/bounties/9e4de32f-ad5f-4830-b3ae-9467b5ab90a1
I found the affected code only in Factory, but I was unable to reproduce the bug with the POC [0]. Upstream fix is here: [1] [0] https://huntr.dev/bounties/9e4de32f-ad5f-4830-b3ae-9467b5ab90a1 [1] https://github.com/vim/vim/commit/5c68617d395f9d7b824f68475b24ce3e38d653a3