Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE: 2022:2102-1 Important: Multiple Vim Heap Overflow Fixes

suse
Calendar Grey June 16, 2022
Dist Suse Esm H88
SUSE Security Update for git addresses 30 vulnerabilities classified as critical severity. Learn more about the flaws and the implemented solutions.
An update that fixes 45 vulnerabilities is now available

Summary

This update for vim fixes the following issues: - CVE-2017-17087: Fixed information leak via .swp files (bsc#1070955). - CVE-2021-3875: Fixed heap-based buffer overflow (bsc#1191770). - CVE-2021-3903: Fixed heap-based buffer overflow (bsc#1192167). - CVE-2021-3968: Fixed heap-based buffer overflow (bsc#1192902). - CVE-2021-3973: Fixed heap-based buffer overflow (bsc#1192903). - CVE-2021-3974: Fixed use-after-free (bsc#1192904). - CVE-2021-4069: Fixed use-after-free in ex_open()in src/ex_docmd.c (bsc#1193466). - CVE-2021-4136: Fixed heap-based buffer overflow (bsc#1193905). - CVE-2021-4166: Fixed out-of-bounds read (bsc#1194093). - CVE-2021-4192: Fixed use-after-free (bsc#1194217). - CVE-2021-4193: Fixed out-of-bounds read (bsc#1194216).

References

#1070955 #1191770 #1192167 #1192902 #1192903

#1192904 #1193466 #1193905 #1194093 #1194216

#1194217 #1194388 #1194872 #1194885 #1195004

#1195203 #1195332 #1195354 #1196361 #1198596

#1198748 #1199331 #1199333 #1199334 #1199651

#1199655 #1199693 #1199745 #1199747 #1199936

#1200010 #1200011 #1200012

Cross- CVE-2017-17087 CVE-2021-3778 CVE-2021-3796

CVE-2021-3872 CVE-2021-3875 CVE-2021-3903

CVE-2021-3927 CVE-2021-3928 CVE-2021-3968

CVE-2021-3973 CVE-2021-3974 CVE-2021-3984

CVE-2021-4019 CVE-2021-4069 CVE-2021-4136

CVE-2021-4166 CVE-2021-4192 CVE-2021-4193

CVE-2021-46059 CVE-2022-0128 CVE-2022-0213

CVE-2022-0261 CVE-2022-0318 CVE-2022-0319

CVE-2022-0351 CVE-2022-0359 CVE-2022-0361

CVE-2022-03...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:2102-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here