Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-68074
HistoryOct 08, 2022 - 12:00 a.m.

Vim Resource Management Error Vulnerability (CNVD-2022-68074)

2022-10-0800:00:00
China National Vulnerability Database
www.cnvd.org.cn
20
vim
resource management
error
vulnerability
versions
confusion
directive
freeing memory
did_set_string_option
attacker
exploit
crash
arbitrary code
cnvd

EPSS

0.001

Percentile

40.9%

Vim is a cross-platform text editor, and a security vulnerability exists in versions prior to Vim 9.0.0614. The vulnerability stems from a confusion in the program’s directive for freeing memory in the did_set_string_option function. An attacker could exploit this vulnerability to potentially crash the program, execute arbitrary code, etc.