MGASA-2023-0305 - Updated vim packages fix security vulnerabilities

Publication date: 27 Oct 2023
URL: https://advisories.mageia.org/MGASA-2023-0305.html
Type: security
Affected Mageia releases: 8, 9
CVE: CVE-2023-5441,
     CVE-2023-5535

The updated packages fix security vulnerabilities:

NULL Pointer Dereference in GitHub repository vim/vim prior to
20d161ace307e28690229b68584f2d84556f8960. (CVE-2023-5441)

Use After Free in GitHub repository vim/vim prior to v9.0.2010.
(CVE-2023-5535)

References:
- https://bugs.mageia.org/show_bug.cgi?id=32428
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VDDWD25AZIHBAA44HQT75OWLQ5UMDKU3/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5441
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5535

SRPMS:
- 9/core/vim-9.0.2059-1.mga9
- 8/core/vim-9.0.2059-1.mga8

Mageia 2023-0305: vim security update

The updated packages fix security vulnerabilities: NULL Pointer Dereference in GitHub repository vim/vim prior to 20d161ace307e28690229b68584f2d84556f8960

Summary

The updated packages fix security vulnerabilities:
NULL Pointer Dereference in GitHub repository vim/vim prior to 20d161ace307e28690229b68584f2d84556f8960. (CVE-2023-5441)
Use After Free in GitHub repository vim/vim prior to v9.0.2010. (CVE-2023-5535)

References

- https://bugs.mageia.org/show_bug.cgi?id=32428

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VDDWD25AZIHBAA44HQT75OWLQ5UMDKU3/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5441

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5535

Resolution

MGASA-2023-0305 - Updated vim packages fix security vulnerabilities

SRPMS

- 9/core/vim-9.0.2059-1.mga9

- 8/core/vim-9.0.2059-1.mga8

Severity
Publication date: 27 Oct 2023
URL: https://advisories.mageia.org/MGASA-2023-0305.html
Type: security
CVE: CVE-2023-5441, CVE-2023-5535

Related News