CVE-2022-3324: Stack-based Buffer Overflow in vim/vim
Last updated 24 July 2024
Other sources
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/vimto a version that resolves this vulnerability.Fixed in 2:8.2.2434-3+deb11u3Fixed in 2:9.0.1378-2+deb12u2Fixed in 2:9.1.1230-1 - Upgrade
Upgrade
vim/vimto a version that resolves this vulnerability.Fixed in 9.0.0598
Event History
Frequently Asked Questions
What is CVE-2022-3324?
CVE-2022-3324 is a stack-based buffer overflow vulnerability in the GitHub repository vim/vim prior to version 9.0.0598.
How does CVE-2022-3324 affect Ubuntu?
CVE-2022-3324 affects Ubuntu versions 2:7.4.1689-3ubuntu1.5+ and 9.0.0598 and later.
How does CVE-2022-3324 affect Debian?
CVE-2022-3324 affects Debian versions 2:8.1.0875-5+deb10u2 and 2:8.2.2434-3+deb11u1, as well as versions 2:9.0.1378-2 and 2:9.0.1894-1.
Is there a fix available for CVE-2022-3324?
Yes, the fix for CVE-2022-3324 is included in version 9.0.0598 of the vim/vim repository.
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-3324?
The Common Weakness Enumeration (CWE) ID for CVE-2022-3324 is CWE-119.