Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Mageia 9: MGASA-2024-0285 Critical: Vim Use-After-Free Threats

mageia
Calendar Grey September 9, 2024
Dist Mageia Esm H88
Uncover essential news in MGASA-2024-0290 focusing on memory corruption vulnerabilities in Emacs, bolstering Mageia's defenses.
Use-after-free in tagstack_clear_entry() in Vim < v9.1.0647

Summary

Use-after-free in tagstack_clear_entry() in Vim < v9.1.0647. (CVE-2024-41957) Use-after-free in alist_add() in Vim < v9.1.0678. (CVE-2024-43374)

References

- https://bugs.mageia.org/show_bug.cgi?id=33504

- https://openwall.com/lists/oss-security/2024/08/01/1

- https://openwall.com/lists/oss-security/2024/08/01/2

- https://openwall.com/lists/oss-security/2024/08/15/6

- https://openwall.com/lists/oss-security/2024/08/22/3

- https://openwall.com/lists/oss-security/2024/08/25/1

- https://openwall.com/lists/oss-security/2024/08/31/1

- https://www.cve.org/CVERecord?id=CVE-2024-41957

- https://www.cve.org/CVERecord?id=CVE-2024-43374

Resolution

SRPMS

- 9/core/vim-9.1.719-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 09 Sep 2024
URL: https://advisories.mageia.org/MGASA-2024-0285.html
Type: security
CVE: CVE-2024-41957, CVE-2024-43374

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here