Bugzilla – Bug 1200697
VUL-1: CVE-2022-2124: vim: out of bounds read in current_quote()
Last modified: 2022-06-20 09:15:23 UTC
CVE-2022-2124 Buffer Over-read in GitHub repository vim/vim prior to 8.2. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-2124 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2124 https://github.com/vim/vim/commit/2f074f4685897ab7212e25931eeeb0212292829f http://www.cvedetails.com/cve/CVE-2022-2124/ https://huntr.dev/bounties/8e9e056d-f733-4540-98b6-414bf36e0b42
Reproduced the crash on SUSE:SLE-15:Update and openSUSE:Factory. On SUSE:SLE-11-SP2:Update and SUSE:SLE-12:Update the input causes the program to hang.