SUSE Security Update: Security update for vim
______________________________________________________________________________

Announcement ID:    SUSE-SU-2016:2942-1
Rating:             important
References:         #1010685 #988903 
Cross-References:   CVE-2016-1248
Affected Products:
                    SUSE Linux Enterprise Server for Raspberry Pi 12-SP2
                    SUSE Linux Enterprise Server 12-SP2
                    SUSE Linux Enterprise Server 12-SP1
                    SUSE Linux Enterprise Desktop 12-SP2
                    SUSE Linux Enterprise Desktop 12-SP1
______________________________________________________________________________

   An update that solves one vulnerability and has one errata
   is now available.

Description:


   This update for vim fixes the following security issues:

   - Fixed CVE-2016-1248 an arbitrary command execution vulnerability
     (bsc#1010685)

   This update for vim fixes the following issues:

   - Fix build with Python 3.5. (bsc#988903)


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2:

      zypper in -t patch SUSE-SLE-RPI-12-SP2-2016-1721=1

   - SUSE Linux Enterprise Server 12-SP2:

      zypper in -t patch SUSE-SLE-SERVER-12-SP2-2016-1721=1

   - SUSE Linux Enterprise Server 12-SP1:

      zypper in -t patch SUSE-SLE-SERVER-12-SP1-2016-1721=1

   - SUSE Linux Enterprise Desktop 12-SP2:

      zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2016-1721=1

   - SUSE Linux Enterprise Desktop 12-SP1:

      zypper in -t patch SUSE-SLE-DESKTOP-12-SP1-2016-1721=1

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64):

      gvim-7.4.326-7.1
      gvim-debuginfo-7.4.326-7.1
      vim-7.4.326-7.1
      vim-debuginfo-7.4.326-7.1
      vim-debugsource-7.4.326-7.1

   - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (noarch):

      vim-data-7.4.326-7.1

   - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le x86_64):

      gvim-7.4.326-7.1
      gvim-debuginfo-7.4.326-7.1
      vim-7.4.326-7.1
      vim-debuginfo-7.4.326-7.1
      vim-debugsource-7.4.326-7.1

   - SUSE Linux Enterprise Server 12-SP2 (noarch):

      vim-data-7.4.326-7.1

   - SUSE Linux Enterprise Server 12-SP1 (ppc64le s390x x86_64):

      gvim-7.4.326-7.1
      gvim-debuginfo-7.4.326-7.1
      vim-7.4.326-7.1
      vim-debuginfo-7.4.326-7.1
      vim-debugsource-7.4.326-7.1

   - SUSE Linux Enterprise Server 12-SP1 (noarch):

      vim-data-7.4.326-7.1

   - SUSE Linux Enterprise Desktop 12-SP2 (noarch):

      vim-data-7.4.326-7.1

   - SUSE Linux Enterprise Desktop 12-SP2 (x86_64):

      gvim-7.4.326-7.1
      gvim-debuginfo-7.4.326-7.1
      vim-7.4.326-7.1
      vim-debuginfo-7.4.326-7.1
      vim-debugsource-7.4.326-7.1

   - SUSE Linux Enterprise Desktop 12-SP1 (noarch):

      vim-data-7.4.326-7.1

   - SUSE Linux Enterprise Desktop 12-SP1 (x86_64):

      gvim-7.4.326-7.1
      gvim-debuginfo-7.4.326-7.1
      vim-7.4.326-7.1
      vim-debuginfo-7.4.326-7.1
      vim-debugsource-7.4.326-7.1


References:

   https://www.suse.com/security/cve/CVE-2016-1248.html
   https://bugzilla.suse.com/1010685
   https://bugzilla.suse.com/988903

SuSE: 2016:2942-1: important: vim

November 29, 2016
An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is ...

Summary

This update for vim fixes the following security issues: - Fixed CVE-2016-1248 an arbitrary command execution vulnerability (bsc#1010685) This update for vim fixes the following issues: - Fix build with Python 3.5. (bsc#988903) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2016-1721=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2016-1721=1 - SUSE Linux Enterprise Server 12-SP1: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2016-1721=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2016-1721=1 - SUSE Linux Enterprise Desktop 12-SP1: zypper in -t patch SUSE-SLE-DESKTOP-12-SP1-2016-1721=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): gvim-7.4.326-7.1 gvim-debuginfo-7.4.326-7.1 vim-7.4.326-7.1 vim-debuginfo-7.4.326-7.1 vim-debugsource-7.4.326-7.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (noarch): vim-data-7.4.326-7.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le x86_64): gvim-7.4.326-7.1 gvim-debuginfo-7.4.326-7.1 vim-7.4.326-7.1 vim-debuginfo-7.4.326-7.1 vim-debugsource-7.4.326-7.1 - SUSE Linux Enterprise Server 12-SP2 (noarch): vim-data-7.4.326-7.1 - SUSE Linux Enterprise Server 12-SP1 (ppc64le s390x x86_64): gvim-7.4.326-7.1 gvim-debuginfo-7.4.326-7.1 vim-7.4.326-7.1 vim-debuginfo-7.4.326-7.1 vim-debugsource-7.4.326-7.1 - SUSE Linux Enterprise Server 12-SP1 (noarch): vim-data-7.4.326-7.1 - SUSE Linux Enterprise Desktop 12-SP2 (noarch): vim-data-7.4.326-7.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): gvim-7.4.326-7.1 gvim-debuginfo-7.4.326-7.1 vim-7.4.326-7.1 vim-debuginfo-7.4.326-7.1 vim-debugsource-7.4.326-7.1 - SUSE Linux Enterprise Desktop 12-SP1 (noarch): vim-data-7.4.326-7.1 - SUSE Linux Enterprise Desktop 12-SP1 (x86_64): gvim-7.4.326-7.1 gvim-debuginfo-7.4.326-7.1 vim-7.4.326-7.1 vim-debuginfo-7.4.326-7.1 vim-debugsource-7.4.326-7.1

References

#1010685 #988903

Cross- CVE-2016-1248

Affected Products:

SUSE Linux Enterprise Server for Raspberry Pi 12-SP2

SUSE Linux Enterprise Server 12-SP2

SUSE Linux Enterprise Server 12-SP1

SUSE Linux Enterprise Desktop 12-SP2

SUSE Linux Enterprise Desktop 12-SP1

https://www.suse.com/security/cve/CVE-2016-1248.html

https://bugzilla.suse.com/1010685

https://bugzilla.suse.com/988903

Severity
Announcement ID: SUSE-SU-2016:2942-1
Rating: important

Related News