Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Slackware 15.0: 2022-089-01 Critical: Vim Memory Exploit Fix

slackware
Calendar Grey March 30, 2022
Dist Slackware Esm H88
Essential vim updates have been released for Slackware 15.0 to resolve significant security vulnerabilities and improve overall system safety.
New vim packages are available for Slackware 15.0 and -current to fix a security issue

Summary

Here are the details from the Slackware 15.0 ChangeLog: patches/packages/vim-8.2.4649-i586-1_slack15.0.txz: Upgraded. Fixes a use-after-free in utf_ptr2char in vim/vim prior to 8.2.4646. This vulnerability is capable of crashing software, bypassing protection mechanisms, modifying memory, and possibly execution of arbitrary code. Thanks to marav for the heads-up. For more information, see: https://www.cve.org/CVERecord?id=CVE-2022-1154 https://huntr.com/bounties/7f0ec6bc-ea0e-45b0-8128-caac72d23425 https://github.com/vim/vim/commit/b55986c52d4cd88a22d0b0b0e8a79547ba13e1d5 (* Security fix *) patches/packages/vim-gvim-8.2.4649-i586-1_slack15.0.txz: Upgraded.

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated packages for Slackware 15.0:
Updated packages for Slackware x86_64 15.0:
Updated packages for Slackware -current:
Updated packages for Slackware x86_64 -current:

MD5 Signatures

Slackware 15.0 packages: e256ba90d3a861c2d0ae52b2c0078498 vim-8.2.4649-i586-1_slack15.0.txz d5bd26402ae3338284f509b5f6ade6c9 vim-gvim-8.2.4649-i586-1_slack15.0.txz
Slackware x86_64 15.0 packages: df88ffc4da35ce29ddc0be2c8e30de84 vim-8.2.4649-x86_64-1_slack15.0.txz ff9f02cd841e6eb5ea55c3a51d33b983 vim-gvim-8.2.4649-x86_64-1_slack15.0.txz
Slackware -current packages: 5870187dd239ac2b09c0f42542dfb8ae ap/vim-8.2.4649-i586-1.txz 69a20480ac90589d0aadc1958a952d32 xap/vim-gvim-8.2.4649-i586-1.txz
Slackware x86_64 -current packages: eda2009b0296ed29ba735394c34f1419 ap/vim-8.2.4649-x86_64-1.txz a4fd425ca055db0e1ac4b18fb002bbfe xap/vim-gvim-8.2.4649-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the packages as root: # upgradepkg vim-8.2.4649-i586-1_slack15.0.txz vim-gvim-8.2.4649-i586-1_slack15.0.txz

Related News

Your message here