CVE-2022-1674
MEDIUMvim < 8.2.4938 - Denial of Service via NULL Pointer Dereference in vim_regexec_string
Title source: llmDescription
NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in GitHub repository vim/vim prior to 8.2.4938. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 allows attackers to cause a denial of service (application crash) via a crafted input.
References (10)
Core 10
Core References
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ODXVYZC5Z4XRRZK7CK6B6IURYVYHA25U/
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IUPOLEX5GXC733HL4EFYMHFU7NISJJZG/
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFAZTAT5CZC2R6KYDYA2HBAVEDSIX6MW/
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202208-32
Mailing List, Release Notes, Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Oct/41
Mailing List mailing-list
http://seclists.org/fulldisclosure/2022/Oct/28
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202305-16
Patch, Third Party Advisory
https://github.com/vim/vim/commit/a59f2dfd0cf9ee1a584d3de5b7c2d47648e79060
Exploit, Patch, Third Party Advisory
https://huntr.dev/bounties/a74ba4a4-7a39-4a22-bde3-d2f8ee07b385
Release Notes, Third Party Advisory
https://support.apple.com/kb/HT213488
Scores
CVSS v3
5.5
EPSS
0.0015
EPSS Percentile
34.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Details
CWE
CWE-476
Status
published
Products (5)
apple/macos
< 13.0
fedoraproject/fedora
34
fedoraproject/fedora
35
fedoraproject/fedora
36
vim/vim
< 8.2.4938
Published
May 12, 2022
Tracked Since
Feb 18, 2026