From 2327cc74ccee6a2e0c356c47549ab5a7a8e7a29f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E6=9D=8E=E6=96=87=E6=9D=B0?= Date: Fri, 21 Oct 2022 10:18:31 +0800 Subject: [PATCH] ADD CVE-2022-0729. --- cve/vim/2022/CVE-2022-0729/README.md | 0 cve/vim/2022/CVE-2022-0729/png/poc.png | Bin 0 -> 14207 bytes cve/vim/2022/CVE-2022-0729/poc | Bin 0 -> 107 bytes cve/vim/2022/yaml/CVE-2022-0729.yaml | 19 +++++++++++++++++++ vulnerability_list.yaml | 2 ++ 5 files changed, 21 insertions(+) create mode 100644 cve/vim/2022/CVE-2022-0729/README.md create mode 100644 cve/vim/2022/CVE-2022-0729/png/poc.png create mode 100644 cve/vim/2022/CVE-2022-0729/poc create mode 100644 cve/vim/2022/yaml/CVE-2022-0729.yaml diff --git a/cve/vim/2022/CVE-2022-0729/README.md b/cve/vim/2022/CVE-2022-0729/README.md new file mode 100644 index 00000000..e69de29b diff --git a/cve/vim/2022/CVE-2022-0729/png/poc.png b/cve/vim/2022/CVE-2022-0729/png/poc.png new file mode 100644 index 0000000000000000000000000000000000000000..7101c6acf2519a8313b5f84b06d475501043a450 GIT binary patch literal 14207 zcmc(`byQtJ^DP(%!QI{6AxLm{cXtRL+}+*X3GVLh5Zv8^26uuPk!EOntp7@GBo*H-TTU02On?CaL8o1nlV&U7={E zh~nsiC?>*BU|=?IUs`9sXYqpJ^vU3Z!-j6=;qeaTkgPA1n4+BhwDH6~<y!&v^Gu(UipOyD+fwgJk}%OV zyC?lkV`nL$Po4U!ZBOFbZ+u2H-`&-|y6_v4(Q(3&2n39GB`~!r<#0Z5+FUF)(sXwxT12L(O z`9&aDqzZ@h=*gw}7)eT!`QlY`m>>{4Z_cnDwRfSDoqV(h?;!2{!VJ`}y6;G3e0+#D zp93ipFYT7RvC2+I#Vk=#y(i=L+oeA0ftj#p-f7>pea*PU^Ep~3qw>(NlDFjA22A=F zBUQ1lQc@o%0ngwcfPzdvfB>F=03S@i2e3Zb!2f;&%$fc1-}8r*-(RADRDJyLfjM4G zkWbMW=p+NoJznT_Ad6Un@(=`=0v=yph?)sbMuxA;mE}4rcoF`3+_6DHrVA9<5t+*( zDD)E_{Gq5yo}ajkC_X`awD!>HSJt-_we=*6#Wjl|e#al5vnEbgzV2l_jJLLSW;~2> zdKT~NsG>YHf~bzrkgKP_I0={}se+KO&gG)f@PL~O<$F>)`K|~NI?T_}3+DPwU=$Ib(3fe{!j%}|9~DR}ruR8*t76|rlt z?HAb0Xn&ylY_+_=f!wFF)kLQqZs4wW zzkI@Ik0ZlJU!3=r(Bx!gCntq|zKH!XM6`G%HL47m;h862z}zi6iKtoophBBz5KGV8fM zBM_zJZE^6FizMNPK&AAP&wd}_7iod>OW_FIu3c4!DG}gtgYU^&2%c+{=>@?c1N($Xm1O%Tpn%ErG$6(_Vi9yKLv+}d-v;CNA(dQ z;sgD@O!`2sD^e(@S_vaE4$_vpcnINx1}uFT%F(-v5rT1IOW=iI%*rFBf=1+aw?%Y> zD$0Cyg8BO4%|Q z2N49{$S6g;zFwD=Zl{NJ1n%)ueBq~y6tXs!kw1!sDmzaDJa7vgWptG^^ye% zi=;pZE5+o?AU%hQ64dr`OA)BUlV>qr(g)T)n{ej=O> z_6#A{jt?mCiU{hYPp_NY+&xBz5s-xMq2)G>HZh9h(lJ`G;9`c);B9@H5E!NDamJW~ z&}-k8t)s?5P^p)ns?F36>Jb9-w~|NqFE0+-n70%Z6T@h*+Q`qsntl_zZZ)i8mmYb= zLF({C-y(=<+Ro9Sze|!~FdpYz^?VxpDF6&67FQ#JY zMMYW3FuP=d`i4c+j5(s{IC2XlM5gv|Or{t)>1h(4^)NCSqPFT-S5uJ5S36Z|DdJYa zFupq8c;XAVeAnfca@DyXz%rj;#42xucf9))PN!sduc4Un+hjQPgX($mB`*b+hM0e~ z9qM98Ht&*eXca{YwDfhs8)I$9k%=qs7G3S-HawPoylAkVLcE!dBQH)5|K*5+sokbJLA1B54 z5tia*buJq$ABJFi9GDk%Z6>>g)q*@MjeUFJHahp$M9$^ieXG)e=1_AmNwlp!xBwT_ zEiEVM}Kzg7<7{-j~Gok*~s^7JQs}3kAS7O6HEV+?cj}p1wS>B<;g0_P2~2k&^v9qI7i^%Z)cCHx0Y!4f;5ni=U1HVcFX(Paa@05Dqz2*u%Fe=ZG zXQW|Qs9W(OD`uq3=8M=HeeX&aU(OSXSdA;w-+{R6XAlgd?7kc2b$R5`cYR5TouNMV z(8TT$hq6b60*>~|F0!#g8yLPF{j6+-k}H1y(e!)w2nD2kjCPT>dP<2^?^B&((6sdt z{h9hb6qymmFw0I(&1CRp`2+X~u3vm{Qm*})97w(}q0?p7Foos-7E=}8<6S3WmOHx? z1}CaHNupIM0bMb@0y zt3B2xk~F^W#>oSS`+5nkH^VzI80_gy2vjb32m?Ak*`tCXjCKr{+8Oh{%hm5*(Lk1k z+CI@xIeMeCL8ev=zI~Epc3&ZGBUHDpg^gR&rJ)FEhj24l@NR`31~?7F)ghKfNQ~=? zUGC=)hYt@y8L-Bw3*I!O#v{_q#LU(*=wFT8xh>fpkFBS}l+9to|3U*V@IEP!hvt|=CgV!2 zmUL1;v7;O&V}Zb}^p9mDi4ZaBA(N|>sqs0dw8RcLBcq-s{dc?tLaZX%tO+7((n9We zLxc-E=b})LAyVdGSthwn{Afj4sHw_etIIg5pQyZrxDc4ycy7Szk&!D7Gc}9~C9`!Q$RS8%`N-v%|vgzfMaqiV{ylVJrU)q8EPB%^6cOAl>Zn z7euzYYp*-Jv&x@S)yFOku$4{bEXaSqZABgMg5|g&nm;4_0O1@7_>!p(l5K9fIPtW3 z5a7Un&GO~~TH7?W{@tcD@w=S&wU-l)qhS?Vf<`0{+{HbS21vL@E{wn>XjR~ z6U4BBBqkA2vv}8(nh{wg(|QTKRa!)xB<-LgpYoWy8|_we2d-$)5W4u2S={rmOb+}WvuXYETLY*8C4_PNGp zR(`3d;8tvpuoPinXOvKd4girP#d?^;CA?U#qAM@Vs9V;c4mdbe6>?B9)FCq z+YfhXh{9ri+(kxcc@?TQ8HxLhpUT}|+cEs=eww3ky*c*zbY;BtgrTE*(Zhz$z5_d(IIc^tI~N+D zT5DFlX1=H;z$s_ZG*a7OJKW=J@WKf!W@tNc-irM8ZQn^rZJ6#xhUeh}&sYY~l5io? z_V)JivZDFVl+PWU8OO=O@J*MYo!hlCg}S$JIzJ2XI(wZqB$0TYr6ych^rU*}ZF;Dh z9`>*lwFWy`K;c$dpUY-7JkKKB&$(Z;VboCD;kj$+s88nvz1iuOTZ3~a`-fmGVuE5KxgyA4)kA0MADscz6p%B8=UU3TlmT(MEA zVXbP6_j)PL^nVS$^;&h73pCva-JiB1UCgiGZQgCX6)_hcRWxH}dA;V7yT#z%<%G4A z+D72LkS)y)JnCahvuy z_4LJ=9;~=07#te1PesQg2xDWyw$K&!XMAGf_E_V_U@6@jSZ~lqNO$8}I3P6bip}TY z2tOMai~CX5SbWTY$!JJFJTh|e*w?rwcFH7eYs>gb0$n?v!I3Sw!)iVsm3-T8UwC2O zYE8;*aG7bTu)O&ScFH#)L95u?TB`iwt1>86R{ll0QperKX(|mV(5fTlJ9i`FcF9~P zdqkxcI4o>;5MCQhF8Wt#Nt5E?%eA}Oi`^uhQgSVJrvW6H=Z_HO>N!2p2ycv2DiEO0UMJO;ez;trHFiT;;qRj;%8t59=Dno#zu%YHeK= zUJRe|3mW=SRIX7#f7lv+Js!-B3NO2x9DvlbuFz`5y<4|S`sLu}!T$ms_p8hbNuWN1 z-JuK1N?Q2aw{JHR4$E*55Z$d-osl~`Anv!Fl~pcR%A8-eaW6QtUaxEc%UB~1$L&nV z9x}1iw6M{`aVFh;;rh68yxfkad=Vsa+p}gfsB0oHQV+z04m^7`T`xiQ%w)yD$aoi~ zci&Dx3R{oaL21y{t8L}xOgYg^nkAw?0TB@b1 zCJIXNHd9zc_rk_#-(r%^;CBI$^YkLOCr8VZ=><;fLTct2rg?+*AOIG;q;r3C1056D zUc@zVRfF<(3=bqA1=mAc;pwBSZif87CvV$6c>k5WExB9N{7v2_^IVdx-8o#2YV#92 z3*M~C-&nsL9iF(`8 znIYRjH{D=?rFs$+^BNk~3H#$(t#fe8!WX?NHf_Khj>p~JrIkHhJ}=egcesUWt-}hW zm)FLU+mL>$&(f3ZB7rV&RqgzP(Vfkb zk`|S#fl8&k+hGA#Rv>zU^C@SzqT__@$eP^+Q;M{W!zENZACBiyaAUy{+ark;&8tbh zQM!k!QmW7QQ&>y`D-KQ+OgNB|pTHgYFun@&@2|L~Ev(>f1MK+yS11;(Pxi^dNwM@g#CneyjprZBh+=*!-( z$WN&RThww?Q(QEilV+d~-E*Gw_2zRhyeH|UCr%qL+0dCQR-Hmo%JT9#w;u!OCVp&! zDb&+J0sy~B!b{s{g8Pl1qs-x`#Iv5Xg2XrXH#XGW#tGL!4@T~mS~~li@6RnK|48BK z4T9^o(GwlQ?JTWmLzM7x?O;Rwo?{#SXW{*0%1FD zb>B71t22$@_|}QC0O@BqM%T%AJ3fbcn{Qk~9-vRIp1A*f)f&96zaqJH?a_ee%w|a9 z*LHifyfIm(Rz~mcskFc9VW$MfmhQmr(qea(y0ObBRTzn*C_k3`W6_IuLVUdA@j8y8 zM1`D)NC7%(Srf+W@yO5!XO_pnRsXa}2tXVF;@;$>>#bsp|4H-FN~PSsA>xI4(|_Cv z|BMlCDpZA>{=9%h?HW4VutSJ1$mEk8@|A+Q*x7bZN_>T7k@R)xbhRGJXfW(zE;eK_ zrWsb`s#dqSW^;MHR}jtX!`Curyg^9IH{e_F!EQj7Uy^ngAy%nBnfU2iWJf9vr4XWer^2kL4ThqwFd=$hMO(#Nt-<6Fmmn#izT92xe=>Rc!8M!ss z43#jIn?EvEUoYdOAws%lL{T)~eG;q`&d20FTVzmLpFfe+z}bm**SfOb-(&6^F~U5QAQ$+|U`Qt5?haL-V1?$` z$&119=J~DeGN7gGEFYcc8#OdDc6`vrQ+8$`hXYYI7N?>FSYAx*vn!sWT8XuN$;n0u zQ98Yq%O~J6nvK-m>xRcU<<}PNq~oX8 ze7FMl>tghEw&2Ef7rd+x)5B?W=d1F&U#S_PbU{eM5p60r=s%FupVa;FhRwDtG*+te zbJJd52eTUXE$->j`?8|_^po%DybdEyR-E+K9$_M5nHHOagt_qD!y71ab&ix`xWo#v z#yKjvaNTzF-07ZGE}=pv-+oakDW86!9SQb&($F!QwMPLhI$m3BvWYt<7?tm!5;()A zeg+#mAPWRDnshhXshYo8fKi;OQK@+Tgl2zMz@4<52Z_=gX=O|(qvj9Tx|f;-=PI%0 z0NUXmwxmwodT>)?*AyjOcqL1_Svl!B_hjfip*_>8of%i7@%cMxl8I@vLzFj=vW8&k z56H0O2z$dG7UK3PsIj-HPY<=X#hF1l0cs}PHAs{VXgy66^8uwsS)Xm7Qlk#SgQ+wK zE`Nb2;?km-QX)_&4%OrTCWsP}rBa_Za2jU5hAk_bwiAA(y6lt^2@`1{_tRbQb^%A} z<=q1&0#1c&9Ss{Uo-3U%N2JM!q1=p>-yCQSIUXtl|oCv_`5ncmpfCG<*1aX-Q{ z3ORMA0}=Z%v3R96%8pS#@2#Ztyp6IDACtG&+R^xTBVl9b(W=~~MH_Y2Y}8kUo@KWL z`uYMtKRqPP(x)UEo0?*1ySlh*)lUDEh&0~*JYPFV(xfmd8Ml?JTA?=_l$CSeH(BX< z#eS?9tjEWOoj0dJ3q*k9@&+%Q&B6D0Dq5(Cfl8+x=yBM<kdWQeuVH7^8EEdM1SK@Vn<*TfH64@MX#ify*uNi2xdBElue5yzZfj zZkTnCz+hG!UEfa+Q8=4%snm$9un>z7SZ|yQw)97{jRK8Wd22^SA}%s|a6wO&DElv0 z${{?NhY4;v9+|QRO`hCQ1*1zt?tRx6&L6)d_ek8xQ~L)(E3|la!o1E=FV5Dm1oG$^ z`TIv}dPO41dpD4b;$4PsDtEGAAN;g6qM?vz)zAIZ6-@mO=3-1kOK2zvW=872rVjQO z^Qc8)XYU?29UPeKglv5|6gdd7CcU&*re&K^y3I^VNGSb;^>(#QrP|=0A4>Z$q({93 zHMpq;{1}~>YXKmTf*i2NyHNdGeJ1rS?L5liv zPJnvnmgp95h#wI6OkQDpc1+LEBcg-GbY{+Uy_AD)+dFf;+dkKGD!JH7`Ml4|-lA={ zR$gfTz2kY>%b!~TJkx87gkf%yI57$@;)8&)s00`N zLPnD)-l3kP#;?zQ3P0C!xF~&Z^dH3x=rWTKa3Ht4YUeQN)8HbCugrr|%`06l#mCM_)(eEt&SYh|lLd0_S^0Tl~CCb1~xJ=a&_E!4t#Lj_z;%Aa5!pS_2tnr3_r=;*J@P$4tR)X9F4wT z4RgJ|0TOdt2-SOjsE)^r`O3sNw8&Py{jMKz`f{Am*d|qDFIcVCsa=Dn>+)7(|I)UA zdzUG~Bn)nIe53o1>~d8NE)j~aq|9PX>-l|4A0EQr|$J{2RtJBF9S5W>^8?WB#a1<(n>xQW#offL&sb-vHlr)ahU$ZGgk&#bKptB(X ztuU6%pi%bKyyx>oq?}DY?o|67Y`uiaRklXs6(B#)mL4(ci9^yLc-&MHfZ z9Q?~9|Gsb10{I~mg@p$5THIX)RO<__#3K{9HzMh{-_U$rwWi@ty==Jr@nF`{9@~JN z+P2q{7La-*aeozs6V1)8a@Q$dHiG2yblNJh#=}1Z(gZoxvtKBcMl1+niCheah=P)@ zEl(y$TZ%*K?t}hb4FK$;><*CUpfzT}5WxoXG+zLno0DAy4yd&W$EaRDP4GAolH^CE z+9;(BrH3!H3E7e0H@V)Zf9GyfhSp+3i@Ab3SLumFK@o1_-jd2sA$^~>}$qd)&C zciYvxp#9-Ah78wBo9qQw;G5?)?z*QNu(peX@7glY+|?%cJM|7Ia5PDD>Ci$uYhKrw z5Ku56#BHSc^H0ruK0ZZ2_dN4+zAQ$Y%pDZEAM7QnGcnUJD(|UYHMoCFJ7c(y+)}Nw z4pFzD?=XTIN>X$$FJX6(%CNPW2na*{2?!SSuMhSUf>YZj9$~Nu77m*4I)eNWzaa~U zQk+2l&sxjs0Gs6-6)#fGndV;*3FOeb*3{OXTqa^_0KLAFQ_$3N=)CaW-uE>IF9=N< zrYh_2B`RJxqUOQH5G8D7cj4bZJT&JY?owN2lD*ef0P`%iiF_fe|F77Bi0@+;(Nzq~ zf?M$&pe}j!F@9#bp{=isuU$tm0(~FKBsc{64xGo%2BI!aW41~D3w zA-ZamN{;;tf}&d4`GD=RO2bxEAS_P!o77V(s7x>GCyBopxM>7(osf8>Uh)4fS5dy5 z7Gpd088^9*HQv%P{NKq{pgujl%T@I2kI+sM;Y|)0FJJ#nQ8dUg46YXsafdSmf6G8N z!CP2#)8K2e&ao(BPhiU&6TjT7<{(&x2@3 z_}s*0%d_rsi3_7C9ej8{&R?XPL|*__*28-R2g|G53LamSF?K*^l?x~O`8FRs7@k{LWvQ;gumhl4QQ{%90@~s$@%)Z9NZ3?cly&eDdXRBY5AB z0ykH-WaRX+G_T2tnLrfhEuKIBP*$oRY8Gj6;oh+?n*j+>U4)jCimx`HDHq)18qwoa z4IL&#+J2jpLMM#@H$(CnGLJy$iGKo3 zdeX92uHzw@9()-;M~5&J&FK4~&d)76XfhfmXEqMuUU($`sxTQ$V)Z4%36&)l4H+1J zuBO&E&c0Q`@Fckm_<1T=p^+K{8zm|fuA@T-a!q^Qd(wcAo4{-AS+hA35+nWzizH85 z(KoWGGsLu55B1x#J%$i6p?lsECRoM;snmbQBxI)B=`T2Q4=~M$)+)SSU@*Rvz(S@@dq? zc5$>}@jHPsH52+~&~&{Byob4l;xT!b&%UR?w0S!M8~#PS8*gzoKSjX*0^W#t>(39GU_qMpmGwZ1?M$9cg9g*_>U82q>btqSvz!f!J z0bOZ$B@onf`hM)p(4o$Vz`?k%W#WlS&0q2pz-DdI)s4NgSp)l-T&7>56C!MWZuDWr zY4>OIy_lXK)HVODsZTCK9DvFss0!>)-j9JFtpRsy<-oJneY7nM!CNgK)E%Wp5m0Yn zc7ohnhD%WVnm|O(03A|!$G`NLOO9}Kp?FLs$NeR6QMX^^^`5MAT||yrG$zg-$;#`JY^6~ab*)f%S?OnkRN zwX*(00mfx4WTk_e7w12 zn^8y^h{}4_s(od}L`V%3|Zel$^NU;(*v%Ns-1vX1jj8EataGumEgX8!Blqsh_Q#7` zd1&SH*yuj*qZpU^ldAp_3Nt;R(K)D~RSKr~^}w?PXUrz9kY%TAKr(%%7Pz>gAao{+ z4ct$k>e6|Dlj786)Bupn&_XGksli;N8xyv&Vic~#WG)Y?2fNd*Ix7F((^7%m@rluYsp^0U--V?R^ zPX%F@;Vt1eh?J0&lU1eOUp4jvLo#z{VaDZNoQ+G%YER^!w8;lhJ`|#Ilb>rRz{4!b zXC?MnPy1tJR~m#YjaI|BX-SKlMlV2pv7+w3`!_l|M+K(MNYp~Plq`x?pjkt)*YSw-0+R4C~=)04|F}@&qy{`NdOs}ItrHfZz)RyDnLMUOKkg3oR#^TUxg|E z-L@p(?X>!<^n2u?D+3_b|H@xVjEWM!y?I{-zb_vr-@9an#knNEH6j$@Js;ncM6{-$ zv1w2mDo)hyEGPg-R_+;?|Jc;kEWwL6ZL8Q{`==|B^37K^K--B>hQDnw(SVY;IM?&| zPfOGQD+91^PQLA5q6;I?mEZj{gzzC0vbi#T2FbFA^PlO}2mo_TYydOgFqnDsS50VQ z0aBDms{t@J;-uNw8?wr_xOL-58yI@`H30~5__MwF4o@*s3>u^U)O&Nof_3w&GkoZM+P9cR_LhkLDh~S z_+LZR#ETOvdbeQzjWHQ8Mp+u1Xkl@HyiwMu7;sc@WaLzc(jkuzG-Rfw#`FN>i-ph7 zo(KPb^ov7p3McE8|8nbda=>;1Y`9!F@qwF}o@*N&t){q5nL3-}fk?vEzTZGv7x@*Py_5wq3V=cdg)ME`@%?it?ey#n>u zp3*C^0N0&52Yz3ndk_HmG9@liZy(`r3AnrAauUAJqYm+(GL6%!J2NtYA~9exzV_F? zkAJfq#QwKH2cSQi4~pM?Z{qX#x96iLXa=r-E&w>4rV$k-D&3ysXxdLllYQUkc%13? zBu_;E4ExP(0)G5Q=Z5bC(8w9VMX?q~xB6~M?dGYslqPO7zsH{@=)klvxH8B;R1}9i z^3yX-koNfgVRyuD><&|)X|LwGEu;H01YQFo-g^6`ZGZyIVuI`FFGx-ffj8N!JN5(I zq~aib&0JA}r?t)H-K#c;0AMXklVNt)aR*)7_inN*)gM=DpAYg!c!#R41&Du}oCZMA zBE!)AgL@fx0J&6Nrzo)?y4av7(YW9JA6cLfAjTA^w;vo60o*j5|Lr^XkUv}Hcc<5z zHD&)gMFY45Kqsh`i8k=As|L#YkAEwanpHtJobUSjgQ2bhrn76xF#V>JDL+>ssVUF^|7GB=%( zv-RnH(a#|O)0Uf%Xm*GRu>!c?aykpXFM5aQU&Ly90QgWc)Wkc-=S}yU;QNCPNw}Jc ze-BP?kYD_OgAU-1BUe35|C~7vL{nTs7T}$h;`P@ppA8`YWjZq;*90^otU2l}M3kpl z0OWZpL;oi-9Vh;Gyg~Z1CIBRO73!h?b$mB5IdjSp>&Ow@CD^*=NEzbdz1?Z8@@yl> z7!A7r^Pke+0R-Si!IB`+ouPo~N7u literal 0 HcmV?d00001 diff --git a/cve/vim/2022/CVE-2022-0729/poc b/cve/vim/2022/CVE-2022-0729/poc new file mode 100644 index 0000000000000000000000000000000000000000..8efa27d0ff146b9fc1925958b1dd04f4f8f0d3ae GIT binary patch literal 107 zcmXRbR!}fLrKw