CVE-2022-4141: Heap-based Buffer Overflow in vim/vim
Published Nov 25, 2022
·Updated
Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.
Affected Software
3 affected components
vim Vim<=9.0.0946
Fedoraproject Fedora=36
Fedoraproject Fedora=37
Remediation
Event History
Nov 25, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-4141?
The severity of CVE-2022-4141 is high.
2
How does CVE-2022-4141 affect Vim and Fedora?
CVE-2022-4141 affects Vim versions 9.0.0946 and below, as well as Fedora versions 36 and 37.
3
What is the vulnerability type of CVE-2022-4141?
The vulnerability type of CVE-2022-4141 is a heap-based buffer overflow.
4
How can an attacker exploit CVE-2022-4141?
An attacker can exploit CVE-2022-4141 by using the CTRL-W gf command in the expression used in the RHS of the substitute command in Vim.
5
How can I fix the vulnerability in Vim and Fedora?
To fix the vulnerability in Vim, update to version 9.0.0947 or later. For Fedora, apply the appropriate security patches or updates.