Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Fedora 25: Security Update for Vim Affects Integer Overflow Issues

fedora
Calendar Grey March 2, 2017
Scroller Fedora
Recent vim security patch for Fedora tackles integer overflow vulnerabilities that may affect memory allocation efficiency.
The newest upstream commit, CVE-2017-6350 vim: Integer overflow at an unserialize_uep memory allocation site, CVE-2017-6349 vim: Integer overflow at a u_read_undo memory allocation...

Summary

VIM (VIsual editor iMproved) is an updated and improved version of the

vi editor. Vi was the first real screen-based editor for UNIX, and is

still very popular. VIM improves on vi by adding new features:

multiple windows, multi-level undo, block highlighting and more.

Update Information:

The newest upstream commit, CVE-2017-6350 vim: Integer overflow at an unserialize_uep memory allocation site, CVE-2017-6349 vim: Integer overflow at a u_read_undo memory allocation site

Change Log

References


[ 1 ] Bug #1427944 - CVE-2017-6349 vim: Integer overflow at a u_read_undo memory allocation site https://bugzilla.redhat.com/show_bug.cgi?id=1427944 [ 2 ] Bug #1427945 - CVE-2017-6350 vim: Integer overflow at an unserialize_uep memory allocation site https://bugzilla.redhat.com/show_bug.cgi?id=1427945

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade vim' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
important
Lowest
Low
Medium
High
Critical

Name: vim
Product: Fedora 25
Version: 8.0.386
Release: 1.fc25
Summary: The VIM editor

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.