CVE-2022-1160

NameCVE-2022-1160
Descriptionheap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
vim (PTS)buster2:8.1.0875-5+deb10u2fixed
buster (security)2:8.1.0875-5+deb10u6fixed
bullseye2:8.2.2434-3+deb11u1fixed
bookworm2:9.0.1378-2fixed
trixie2:9.1.0016-1fixed
sid2:9.1.0199-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
vimsource(unstable)(not affected)

Notes

- vim <not-affected> (Vulnerable code introduced later)
https://huntr.dev/bounties/a6f3222d-2472-439d-8881-111138a5694c/
Introduced by: https://github.com/vim/vim/commit/85b43c6cb7d56919e245622f4e42db6d8bee4194 (v8.2.4603)
Fixed by: https://github.com/vim/vim/commit/2bdad6126778f907c0b98002bfebf0e611a3f5db (v8.2.4647)

Search for package or bug name: Reporting problems