Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

openSUSE: 2019:1796-1 Important: neovim Update Fixes Security Issue

opensuse
Calendar Grey July 23, 2019
Dist Opensuse Esm H88
A significant update for neovim on openSUSE has been released, addressing a major bug. Please refer to the guidelines for patch installation.
An update that fixes one vulnerability is now available.

Description

This update for neovim fixes the following issues:

neovim was updated to version 0.3.7:

* CVE-2019-12735: source should check sandbox (boo#1137443)

* genappimage.sh: migrate to linuxdeploy

Version Update to version 0.3.5:

* options: properly reset directories on 'autochdir'

* Remove MSVC optimization workaround for SHM_ALL

* Make SHM_ALL to a variable instead of a compound literal #define

* doc: mention "pynvim" module rename

* screen: don't crash when drawing popupmenu with 'rightleft' option

* look-behind match may use the wrong line number

* :terminal : set topline based on window height

* :recover : Fix crash on non-existent *.swp

Version Update to version 0.3.4:

* test: add tests for conceal cursor movement

* display: unify ursorline and concealcursor redraw logic

Version Update to version 0.3.3:

* health/provider: Check for available pynvim when neovim mod is missing

* python#CheckForModule: Use the given module...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15:

zypper in -t patch openSUSE-2019-1796=1

Package List

- openSUSE Backports SLE-15 (noarch):

neovim-lang-0.3.7-bp150.2.9.1

- openSUSE Backports SLE-15 (x86_64):

neovim-0.3.7-bp150.2.9.1

References

https://www.suse.com/security/cve/CVE-2019-12735.html

https://bugzilla.suse.com/1137443

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2019:1796-1
Rating: important
Affected Products: openSUSE Backports SLE-15

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here