CVE-2022-0413
Description
RHSA-2022:0894: vim security update (Moderate)
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Description vim: Use after free in src/ex_cmds.c Red Hat statement Untrusted vim scripts with -s [scriptin] are not recommended to run. CVSS v3: 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 8vim-2:8.0.1763-16.el8_5.12RHSA-2022:08942022-03-15T00:00:00Z Red Hat Enterprise Linuxβ¦
Description
vim: Use after free in src/ex_cmds.c
Red Hat statement
Untrusted vim scripts with -s [scriptin] are not recommended to run.
CVSS v3: 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Errata / fixed releases
| Product | Package | Advisory | Released |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | vim-2:8.0.1763-16.el8_5.12 | RHSA-2022:0894 | 2022-03-15T00:00:00Z |
| Red Hat Enterprise Linux 8 | vim-2:8.0.1763-16.el8_5.12 | RHSA-2022:0894 | 2022-03-15T00:00:00Z |
| Red Hat Enterprise Linux 9 | vim-2:8.2.2637-15.el9 | RHBA-2022:3945 | 2022-05-17T00:00:00Z |
| Red Hat Enterprise Linux 9 | vim-2:8.2.2637-15.el9 | RHBA-2022:3945 | 2022-05-17T00:00:00Z |
Package state
| Product | Package | State |
|---|---|---|
| Red Hat Enterprise Linux 6 | vim | Not affected |
| Red Hat Enterprise Linux 7 | vim | Not affected |
Apply commands
yum update -y vim
# or:
dnf upgrade -y vim
Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | Red Hat Enterprise Linux 6 | Not affected |
| redhat | Red Hat Enterprise Linux 7 | Not affected |
OS impact
SUSE Affected 1 release
| Version | Status | Fixed in |
|---|---|---|
| β | Affected | β |
Debian Mixed 5 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 2:8.2.4659-1 |
| sid | Fixed | 2:8.2.4659-1 |
| forky | Fixed | 2:8.2.4659-1 |
| bullseye | Affected | β |
| bookworm | Fixed | 2:8.2.4659-1 |
Red Hat Fixed 2 releases
| Version | Status | Fixed in |
|---|---|---|
| 9 | Fixed | β |
| 8 | Fixed | β |
Rocky Linux Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 8 | Fixed | β |
References
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.