Synopsis: Important: vim security update
Advisory ID:       SLSA-2019:1774-1
Issue Date:        2019-07-15
CVE Numbers:       CVE-2019-12735
--

Security Fix(es):

* vim/neovim: ':source!' command allows arbitrary command execution via
modelines (CVE-2019-12735)
--

SL6
  x86_64
    vim-X11-7.4.629-5.el6_10.2.x86_64.rpm
    vim-common-7.4.629-5.el6_10.2.x86_64.rpm
    vim-debuginfo-7.4.629-5.el6_10.2.x86_64.rpm
    vim-enhanced-7.4.629-5.el6_10.2.x86_64.rpm
    vim-filesystem-7.4.629-5.el6_10.2.x86_64.rpm
    vim-minimal-7.4.629-5.el6_10.2.x86_64.rpm
  i386
    vim-X11-7.4.629-5.el6_10.2.i686.rpm
    vim-common-7.4.629-5.el6_10.2.i686.rpm
    vim-debuginfo-7.4.629-5.el6_10.2.i686.rpm
    vim-enhanced-7.4.629-5.el6_10.2.i686.rpm
    vim-filesystem-7.4.629-5.el6_10.2.i686.rpm
    vim-minimal-7.4.629-5.el6_10.2.i686.rpm

- Scientific Linux Development Team

SciLinux: SLSA-2019-1774-1 Important: vim on SL6.x i386/x86_64

vim/neovim: ':source!' command allows arbitrary command execution via modelines (CVE-2019-12735) SL6 x86_64 vim-X11-7.4.629-5.el6_10.2.x86_64.rpm vim-common-7.4.629-5.el6_10.2.x86_...

Summary

Important: vim security update



Security Fixes

* vim/neovim: ':source!' command allows arbitrary command execution via modelines (CVE-2019-12735)
SL6 x86_64 vim-X11-7.4.629-5.el6_10.2.x86_64.rpm vim-common-7.4.629-5.el6_10.2.x86_64.rpm vim-debuginfo-7.4.629-5.el6_10.2.x86_64.rpm vim-enhanced-7.4.629-5.el6_10.2.x86_64.rpm vim-filesystem-7.4.629-5.el6_10.2.x86_64.rpm vim-minimal-7.4.629-5.el6_10.2.x86_64.rpm i386 vim-X11-7.4.629-5.el6_10.2.i686.rpm vim-common-7.4.629-5.el6_10.2.i686.rpm vim-debuginfo-7.4.629-5.el6_10.2.i686.rpm vim-enhanced-7.4.629-5.el6_10.2.i686.rpm vim-filesystem-7.4.629-5.el6_10.2.i686.rpm vim-minimal-7.4.629-5.el6_10.2.i686.rpm
- Scientific Linux Development Team

Severity
Advisory ID: SLSA-2019:1774-1
Issued Date: : 2019-07-15
CVE Numbers: CVE-2019-12735

Related News