Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 41: FEDORA-2024-48e080c52f Critical: Vim Buffer Overflow

fedora
Calendar Grey September 13, 2024
Dist Fedora Esm H88
Updates rolled out for Fedora to patch vim, tackling various severe vulnerabilities such as buffer overflow risks and memory leak challenges.
Security fix for CVE-2024-45306 patchlevel 703 Security fixes for CVE-2024-43374, CVE-2024-43802

Summary

VIM (VIsual editor iMproved) is an updated and improved version of the

vi editor. Vi was the first real screen-based editor for UNIX, and is

still very popular. VIM improves on vi by adding new features:

multiple windows, multi-level undo, block highlighting and more.

Update Information:

Security fix for CVE-2024-45306 patchlevel 703 Security fixes for CVE-2024-43374, CVE-2024-43802

Change Log

* Fri Sep 6 2024 Zdenek Dohnal - 2:9.1.719-1 - patchlevel 719 * Fri Aug 30 2024 Zdenek Dohnal - 2:9.1.703-1 - patchlevel 703 * Mon Aug 12 2024 Zdenek Dohnal - 2:9.1.672-1 - patchlevel 672

References


[ 1 ] Bug #2305311 - CVE-2024-43374 vim: use-after-free in alist_add() in src/arglist.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2305311 [ 2 ] Bug #2308491 - CVE-2024-43802 vim: Heap Buffer Overflow in Vim's Typeahead Buffer Handling [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2308491 [ 3 ] Bug #2309344 - CVE-2024-45306 vim: heap-buffer-overflow in Vim [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2309344

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-48e080c52f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: vim
Product: Fedora 41
Version: 9.1.719
Release: 1.fc41
Summary: The VIM editor

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here