Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-2819
HistoryAug 15, 2022 - 12:00 a.m.

CVE-2022-2819

2022-08-1500:00:00
ubuntu.com
ubuntu.com
32
github repository
buffer overflow
version 8.2.2672
commit b2cb6c8b
poc
unix

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

39.3%

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211.

Notes

Author Note
rodrigo-zaiden faulty code was added in version 8.2.2672, with commit b2cb6c8b, so, versions earlier than that are not affected. there is a possibility that version 8.2.2301 (commit 752fc692) is also affected, but the PoC provided didn’t reproduce in this version. Anyway, at least versions prior to 8.2.2301 are not affected.
OSVersionArchitecturePackageVersionFilename
ubuntu22.04noarchvim< 2:8.2.3995-1ubuntu2.11UNKNOWN

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

39.3%