CVE-2022-3324: Stack-based Buffer Overflow in vim/vim
Published Sep 27, 2022
·Updated
Last updated 24 July 2024
Other sources
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.
Affected Software
6 affected componentsFixes available
vim Vim<9.0.0598
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Fedoraproject Fedora=37
Debian Debian Linux=10.0
debian/vim<=2:8.2.2434-3+deb11u1
2:8.2.2434-3+deb11u32:9.0.1378-2+deb12u22:9.1.1230-1
Remediation
Event History
Sep 27, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 12, 2024
Data Sourced
via Launchpad·12:09 AM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:57 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2022-3324?
CVE-2022-3324 is a stack-based buffer overflow vulnerability in the GitHub repository vim/vim prior to version 9.0.0598.
2
How does CVE-2022-3324 affect Ubuntu?
CVE-2022-3324 affects Ubuntu versions 2:7.4.1689-3ubuntu1.5+ and 9.0.0598 and later.
3
How does CVE-2022-3324 affect Debian?
CVE-2022-3324 affects Debian versions 2:8.1.0875-5+deb10u2 and 2:8.2.2434-3+deb11u1, as well as versions 2:9.0.1378-2 and 2:9.0.1894-1.
4
Is there a fix available for CVE-2022-3324?
Yes, the fix for CVE-2022-3324 is included in version 9.0.0598 of the vim/vim repository.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-3324?
The Common Weakness Enumeration (CWE) ID for CVE-2022-3324 is CWE-119.