MGASA-2024-0285 - Updated vim packages fix security vulnerabilities

Publication date: 09 Sep 2024
URL: https://advisories.mageia.org/MGASA-2024-0285.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-41957,
     CVE-2024-43374

Use-after-free in tagstack_clear_entry() in Vim < v9.1.0647.
(CVE-2024-41957)
Use-after-free in alist_add() in Vim < v9.1.0678. (CVE-2024-43374)

References:
- https://bugs.mageia.org/show_bug.cgi?id=33504
- https://openwall.com/lists/oss-security/2024/08/01/1
- https://openwall.com/lists/oss-security/2024/08/01/2
- https://openwall.com/lists/oss-security/2024/08/15/6
- https://openwall.com/lists/oss-security/2024/08/22/3
- https://openwall.com/lists/oss-security/2024/08/25/1
- https://openwall.com/lists/oss-security/2024/08/31/1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-41957
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-43374

SRPMS:
- 9/core/vim-9.1.719-1.mga9

Mageia 2024-0285: vim Security Advisory Updates

Use-after-free in tagstack_clear_entry() in Vim < v9.1.0647

Summary

Use-after-free in tagstack_clear_entry() in Vim < v9.1.0647. (CVE-2024-41957) Use-after-free in alist_add() in Vim < v9.1.0678. (CVE-2024-43374)

References

- https://bugs.mageia.org/show_bug.cgi?id=33504

- https://openwall.com/lists/oss-security/2024/08/01/1

- https://openwall.com/lists/oss-security/2024/08/01/2

- https://openwall.com/lists/oss-security/2024/08/15/6

- https://openwall.com/lists/oss-security/2024/08/22/3

- https://openwall.com/lists/oss-security/2024/08/25/1

- https://openwall.com/lists/oss-security/2024/08/31/1

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-41957

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-43374

Resolution

MGASA-2024-0285 - Updated vim packages fix security vulnerabilities

SRPMS

- 9/core/vim-9.1.719-1.mga9

Severity
Publication date: 09 Sep 2024
URL: https://advisories.mageia.org/MGASA-2024-0285.html
Type: security
CVE: CVE-2024-41957, CVE-2024-43374

Related News