Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 35: FEDORA-2022-3b33d04743 Critical: VIM Security Fixes

fedora
Calendar Grey September 1, 2022
Dist Fedora Esm H88
Vim vulnerabilities resolved in Fedora 35 enhance system safety. Comprehensive update notes and corrective measures available.
Security fixes for CVE-2022-2946, CVE-2022-2923, CVE-2022-2845, CVE-2022-2889

Summary

VIM (VIsual editor iMproved) is an updated and improved version of the

vi editor. Vi was the first real screen-based editor for UNIX, and is

still very popular. VIM improves on vi by adding new features:

multiple windows, multi-level undo, block highlighting and more.

Security fixes for CVE-2022-2946, CVE-2022-2923, CVE-2022-2845, CVE-2022-2889

* Tue Aug 23 2022 Zdenek Dohnal - 2:9.0.246-1

- patchlevel 246

[ 1 ] Bug #2119844 - CVE-2022-2845 vim: Buffer Under-read

https://bugzilla.redhat.com/show_bug.cgi?id=2119844

[ 2 ] Bug #2119864 - CVE-2022-2889 vim: use-after-free in find_var_also_in_script() in evalvars.c

https://bugzilla.redhat.com/show_bug.cgi?id=2119864

[ 3 ] Bug #2120989 - CVE-2022-2923 vim: null pointer dereference in function sug_filltree

https://bugzilla.redhat.com/show_bug.cgi?id=2120989

[ 4 ] Bug #2120993 - CVE-2022-2946 vim: use after free in function vim_vsnprintf_typval

https://bugzilla.redhat.com/show_bug.cgi?id=2120993

su -c 'dnf upgrade --advisory FEDORA-2022-3b33d04743' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it:

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 35
Version: 9.0.246
Release: 1.fc35
Summary: The VIM editor

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here