Lucene search

K
redosRedosROS-20221103-01
HistoryNov 03, 2022 - 12:00 a.m.

ROS-20221103-01

2022-11-0300:00:00
redos.red-soft.ru
6
vim editor
qf_update_buffer
memory release
autocmd handler
remote code execution
unix

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

0.005 Low

EPSS

Percentile

77.5%

Vim text editor vulnerability is related to memory release error in qf_update_buffer function
in the quickfix.c file of the autocmd Handler component. Exploitation of the vulnerability could allow an attacker,
acting remotely, trick the victim into opening a specially crafted file, causing a program crash, and executing arbitrary code.
program crash and execute arbitrary code

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64vim-x11<= 8.2.4701-12UNKNOWN

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

0.005 Low

EPSS

Percentile

77.5%