Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 39: Critical Vim Memory Issues Resolved in 2023-1976197889 Update

fedora
Calendar Grey November 3, 2023
Dist Fedora Esm H88
Important security patch for Fedora 39's vim released, addressing vulnerabilities such as stack overflow and enhancing overall system performance.
Security fix for CVE-2023-5535, CVE-2023-5441 ---- patchlevel 1984 ---- The newest upstream commit

Summary

VIM (VIsual editor iMproved) is an updated and improved version of the

vi editor. Vi was the first real screen-based editor for UNIX, and is

still very popular. VIM improves on vi by adding new features:

multiple windows, multi-level undo, block highlighting and more.

Update Information:

Security fix for CVE-2023-5535, CVE-2023-5441 ---- patchlevel 1984 ---- The newest upstream commit

Change Log

* Wed Oct 18 2023 Zdenek Dohnal - 2:9.0.2048-1 - patchlevel 2048 * Thu Oct 5 2023 Remi Collet - 2:9.0.1984-2 - rebuild for new libsodium * Thu Oct 5 2023 Zdenek Dohnal - 2:9.0.1984-1 - patchlevel 1984 * Mon Oct 2 2023 Zdenek Dohnal - 2:9.0.1968-1 - patchlevel 1968

References


[ 1 ] Bug #2242141 - CVE-2023-5344 vim: Heap-based Buffer Overflow in trunc_string() https://bugzilla.redhat.com/show_bug.cgi?id=2242141 [ 2 ] Bug #2242926 - CVE-2023-5441 vim: NULL pointer dereference in screen_line() in src/screen.c https://bugzilla.redhat.com/show_bug.cgi?id=2242926 [ 3 ] Bug #2244101 - CVE-2023-5535 vim: use after free https://bugzilla.redhat.com/show_bug.cgi?id=2244101

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-1976197889' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: vim
Product: Fedora 39
Version: 9.0.2048
Release: 1.fc39
Summary: The VIM editor

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here