CVE-2022-1621

medium
Published 2022-07-01 Β· Modified 2022-08-05
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.5

Description

Moderate: vim security update

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description vim: heap buffer overflow in vim_strncpy CVSS v3: 7.3 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 8vim-2:8.0.1763-19.el8_6.2RHSA-2022:53192022-06-30T00:00:00Z Red Hat Enterprise Linux 8vim-2:8.0.1763-19.el8_6.2RHSA-2022:53192022-06-30T00:00:00Z Red Hat Enterprise Linux…

Description

vim: heap buffer overflow in vim_strncpy

CVSS v3: 7.3 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8vim-2:8.0.1763-19.el8_6.2RHSA-2022:53192022-06-30T00:00:00Z
Red Hat Enterprise Linux 8vim-2:8.0.1763-19.el8_6.2RHSA-2022:53192022-06-30T00:00:00Z
Red Hat Enterprise Linux 9vim-2:8.2.2637-16.el9_0.2RHSA-2022:52422022-07-01T00:00:00Z
Red Hat Enterprise Linux 9vim-2:8.2.2637-16.el9_0.2RHSA-2022:52422022-07-01T00:00:00Z
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8vim-2:8.0.1763-19.el8_6.2RHSA-2022:53192022-06-30T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6vimOut of support scope
Red Hat Enterprise Linux 7vimOut of support scope

Apply commands

bash fix
Apply RHSA-2022:5319 for Red Hat Enterprise Linux 8
yum update -y vim
# or:
dnf upgrade -y vim

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Fixed 2:9.0.0135-1
sid Fixed 2:9.0.0135-1
forky Fixed 2:9.0.0135-1
bullseye Affected β€”
bookworm Fixed 2:9.0.0135-1
almalinux AlmaLinux Fixed 2 releases
VersionStatusFixed in
9 Fixed vim-X11-8.2.2637-16.el9_0.2.aarch64.rpm
8 Fixed vim-filesystem-8.0.1763-19.el8_6.2.noarch.rpm
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”
rockylinux Rocky Linux Fixed 1 release
VersionStatusFixed in
8 Fixed β€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.