Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Fedora 34: FEDORA-2022-7e9e1ae1fb Moderate: vim Buffer Overflow Risks

fedora
Calendar Grey February 3, 2022
Dist Fedora Esm H88
Fedora 34 has issued vital security updates for Vim, targeting critical vulnerabilities like buffer overflows and out of bounds reads to enhance system security
Security fixes for CVE-2022-0351, CVE-2022-0359 ---- Security fixes for CVE-2022-0213, CVE-2022-0261, CVE-2022-0128, CVE-2022-0318

Summary

VIM (VIsual editor iMproved) is an updated and improved version of the

vi editor. Vi was the first real screen-based editor for UNIX, and is

still very popular. VIM improves on vi by adding new features:

multiple windows, multi-level undo, block highlighting and more.

Security fixes for CVE-2022-0351, CVE-2022-0359 ---- Security fixes for

CVE-2022-0213, CVE-2022-0261, CVE-2022-0128, CVE-2022-0318

* Thu Jan 27 2022 Zdenek Dohnal - 2:8.2.4232-1

- patchlevel 4232

* Mon Jan 24 2022 Zdenek Dohnal - 2:8.2.4198-1

- patchlevel 4198

* Sat Jan 22 2022 Fedora Release Engineering - 2:8.2.4068-2

- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild

[ 1 ] Bug #2043779 - CVE-2022-0213 vim: vim is vulnerable to out of bounds read

https://bugzilla.redhat.com/show_bug.cgi?id=2043779

[ 2 ] Bug #2044607 - CVE-2022-0261 vim: Heap-based Buffer Overflow in block_insert() in src/ops.c

https://bugzilla.redhat.com/show_bug.cgi?id=2044607

[ 3 ] Bug #2044954 - CVE-2022-0128 vim: a heap-based OOB read of size 1

https://bugzilla.redhat.com/show_bug.cgi?id=2044954

[ 4 ] Bug #2045355 - CVE-2022-0318 vim: heap-based buffer overflow in utf_head_off() in mbyte.c

https://bugzilla.redhat.com/show_bug.cgi?id=2045355

[ 5 ] Bug #2046436 - CVE-2022-0351 vim: access of memory location before start of buffer

https://bugzilla.redhat.com/show_bug.cgi?id=2046436

[ 6 ] Bug #2046479 - CVE-2022-0359 vim: heap-based buffer overflow in init_ccline() in ex_getln.c

https://bugzilla.redhat.com/show_bug.cgi?id=2046479

su -c 'dnf upgrade --advisory FEDORA-2022-7e9e1ae1fb' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Product: Fedora 34
Version: 8.2.4232
Release: 1.fc34
Summary: The VIM editor

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here