Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia: 2023-0305 Critical Advisory for Vim Security Risks

mageia
Calendar Grey October 27, 2023
Dist Mageia Esm H88
New vim updates address critical security flaws in Mageia releases 8 and 9, enhancing defense against potential attacks.
The updated packages fix security vulnerabilities: NULL Pointer Dereference in GitHub repository vim/vim prior to 20d161ace307e28690229b68584f2d84556f8960

Summary

The updated packages fix security vulnerabilities:
NULL Pointer Dereference in GitHub repository vim/vim prior to 20d161ace307e28690229b68584f2d84556f8960. (CVE-2023-5441)
Use After Free in GitHub repository vim/vim prior to v9.0.2010. (CVE-2023-5535)

References

- https://bugs.mageia.org/show_bug.cgi?id=32428

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VDDWD25AZIHBAA44HQT75OWLQ5UMDKU3/

- https://www.cve.org/CVERecord?id=CVE-2023-5441

- https://www.cve.org/CVERecord?id=CVE-2023-5535

Resolution

SRPMS

- 9/core/vim-9.0.2059-1.mga9

- 8/core/vim-9.0.2059-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 27 Oct 2023
URL: https://advisories.mageia.org/MGASA-2023-0305.html
Type: security
CVE: CVE-2023-5441, CVE-2023-5535

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here