Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Fedora 35: 2022-6f5e420e52 Critical: VIM Buffer Overflow Fixes

fedora
Calendar Grey August 23, 2022
Dist Fedora Esm H88
Critical security update for Fedora 35 available to fix vim vulnerabilities. Users must update their systems to avoid exploitation risks and ensure security
patchlevel 213 Security fixes for CVE-2022-2819, CVE-2022-2816, CVE-2022-2817

Summary

VIM (VIsual editor iMproved) is an updated and improved version of the

vi editor. Vi was the first real screen-based editor for UNIX, and is

still very popular. VIM improves on vi by adding new features:

multiple windows, multi-level undo, block highlighting and more.

patchlevel 213 Security fixes for CVE-2022-2819, CVE-2022-2816, CVE-2022-2817

* Mon Aug 15 2022 Zdenek Dohnal - 2:9.0.213-1

- patchlevel 213

* Thu Aug 11 2022 Zdenek Dohnal - 2:9.0.189-1

- patchlevel 189

[ 1 ] Bug #2118594 - CVE-2022-2819 vim: heap buffer overflow in compile_lock_unlock() at src/vim9cmds.c

https://bugzilla.redhat.com/show_bug.cgi?id=2118594

[ 2 ] Bug #2119042 - CVE-2022-2816 vim: out-of-bounds read in check_vim9_unlet() at src/vim9cmds.c

https://bugzilla.redhat.com/show_bug.cgi?id=2119042

[ 3 ] Bug #2119043 - CVE-2022-2817 vim: heap use-after-free in string_quote() at src/strings.c

https://bugzilla.redhat.com/show_bug.cgi?id=2119043

su -c 'dnf upgrade --advisory FEDORA-2022-6f5e420e52' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it:

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 35
Version: 9.0.213
Release: 1.fc35
Summary: The VIM editor

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here