CVE-2024-22667

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
05/02/2024
Last modified:
04/11/2025

Description

Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:* 9.0.2142 (excluding)
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*