Bug 1207397 (CVE-2022-47024) - VUL-1: CVE-2022-47024: vim: Null pointer dereference issue in function gui_x11_create_blank_mouse in gui_x11.c
Summary: VUL-1: CVE-2022-47024: vim: Null pointer dereference issue in function gui_x1...
Status: RESOLVED WONTFIX
Alias: CVE-2022-47024
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Zoltan Balogh
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/354444/
Whiteboard: CVSSv3.1:SUSE:CVE-2022-47024:3.3:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-01-23 09:42 UTC by Cathy Hu
Modified: 2023-01-25 08:55 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Cathy Hu 2023-01-23 09:42:52 UTC
CVE-2022-47024

A null pointer dereference issue was discovered in function
gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru 9.0.0339 allows
attackers to cause denial of service or other unspecified impacts.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-47024
https://github.com/vim/vim/commit/a63ad78ed31e36dbdf3a9cd28071dcdbefce7d19
https://www.cve.org/CVERecord?id=CVE-2022-47024
Comment 1 Cathy Hu 2023-01-23 09:43:32 UTC
Affected:
- SUSE:SLE-11-SP2:Update/vim  7.2   

Not Affected:
- SUSE:Carwos:1/vim           9.0.0814
- SUSE:SLE-12:Update/vim      9.0.0814
- SUSE:SLE-15:Update/vim      9.0.1040
- openSUSE:Factory/vim        9.0.1188
Comment 2 Cathy Hu 2023-01-25 08:55:04 UTC
Wontfix:
- SUSE:SLE-11-SP2:Update/vim  7.2 

Closing