Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE Linux Enterprise Micro 5.2: 2022:0736-2 Important: Vim Buffer Overflow

suse
Calendar Grey April 19, 2022
Dist Suse Esm H88
SUSE Security Patch for apache addresses 10 vulnerabilities of critical severity. Update advised for impacted installations.
An update that fixes 14 vulnerabilities is now available

Summary

This update for vim fixes the following issues: - CVE-2022-0318: Fixed heap-based buffer overflow (bsc#1195004). - CVE-2021-3796: Fixed use-after-free in nv_replace() in normal.c (bsc#1190570). - CVE-2021-3872: Fixed heap-based buffer overflow in win_redr_status() drawscreen.c (bsc#1191893). - CVE-2021-3927: Fixed heap-based buffer overflow (bsc#1192481). - CVE-2021-3928: Fixed stack-based buffer overflow (bsc#1192478). - CVE-2021-4019: Fixed heap-based buffer overflow (bsc#1193294). - CVE-2021-3984: Fixed illegal memory access when C-indenting could have led to heap buffer overflow (bsc#1193298). - CVE-2021-3778: Fixed heap-based buffer overflow in regexp_nfa.c (bsc#1190533). - CVE-2021-4193: Fixed out-of-bounds read (bsc#1194216).

References

#1190533 #1190570 #1191893 #1192478 #1192481

#1193294 #1193298 #1194216 #1194556 #1195004

#1195066 #1195126 #1195202 #1195356

Cross- CVE-2021-3778 CVE-2021-3796 CVE-2021-3872

CVE-2021-3927 CVE-2021-3928 CVE-2021-3984

CVE-2021-4019 CVE-2021-4193 CVE-2021-46059

CVE-2022-0318 CVE-2022-0319 CVE-2022-0351

CVE-2022-0361 CVE-2022-0413

CVSS scores:

CVE-2021-3778 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2021-3778 (SUSE): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CVE-2021-3796 (NVD) : 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:H

CVE-2021-3796 (SUSE): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CVE-2021-3872 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:0736-2
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here