Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Ubuntu 4016-1: Critical Vim Issues and Update Instructions

Ubuntu Large Esm H500
Several security issues were fixed in Vim.
=========================================================================Ubuntu Security Notice USN-4016-1
June 11, 2019

vim vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 19.04
- Ubuntu 18.10
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in Vim.

Software Description:
- vim: Vi IMproved - enhanced vi editor

Details:

It was discovered that Vim incorrectly handled certain files.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 16.04 LTS. (CVE-2017-5953)

It was discovered that Vim incorrectly handled certain files.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-12735)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.04:
  vim                             2:8.1.0320-1ubuntu3.1
  vim-common                      2:8.1.0320-1ubuntu3.1
  vim-gui-common                  2:8.1.0320-1ubuntu3.1
  vim-runtime                     2:8.1.0320-1ubuntu3.1

Ubuntu 18.10:
  vim                             2:8.0.1766-1ubuntu1.1
  vim-common                      2:8.0.1766-1ubuntu1.1
  vim-gui-common                  2:8.0.1766-1ubuntu1.1
  vim-runtime                     2:8.0.1766-1ubuntu1.1

Ubuntu 18.04 LTS:
  vim                             2:8.0.1453-1ubuntu1.1
  vim-common                      2:8.0.1453-1ubuntu1.1
  vim-gui-common                  2:8.0.1453-1ubuntu1.1
  vim-runtime                     2:8.0.1453-1ubuntu1.1

Ubuntu 16.04 LTS:
  vim                             2:7.4.1689-3ubuntu1.3
  vim-common                      2:7.4.1689-3ubuntu1.3
  vim-gui-common                  2:7.4.1689-3ubuntu1.3
  vim-runtime                     2:7.4.1689-3ubuntu1.3

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4016-1
  CVE-2017-5953, CVE-2019-12735

Package Information:
  https://launchpad.net/ubuntu/+source/vim/2:8.1.0320-1ubuntu3.1
  https://launchpad.net/ubuntu/+source/vim/2:8.0.1766-1ubuntu1.1
  https://launchpad.net/ubuntu/+source/vim/2:8.0.1453-1ubuntu1.1
  https://launchpad.net/ubuntu/+source/vim/2:7.4.1689-3ubuntu1.3

Ubuntu 4016-1: Critical Vim Issues and Update Instructions

ubuntu
Calendar Grey June 11, 2019
Dist Ubuntu Esm H88
New security patches released for Vim addressing multiple vulnerabilities in several Ubuntu releases, including urgent updates.
Several security issues were fixed in Vim.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04: vim 2:8.1.0320-1ubuntu3.1 vim-common 2:8.1.0320-1ubuntu3.1 vim-gui-common 2:8.1.0320-1ubuntu3.1 vim-runtime 2:8.1.0320-1ubuntu3.1 Ubuntu 18.10: vim 2:8.0.1766-1ubuntu1.1 vim-common 2:8.0.1766-1ubuntu1.1 vim-gui-common 2:8.0.1766-1ubuntu1.1 vim-runtime 2:8.0.1766-1ubuntu1.1 Ubuntu 18.04 LTS: vim 2:8.0.1453-1ubuntu1.1 vim-common 2:8.0.1453-1ubuntu1.1 vim-gui-common 2:8.0.1453-1ubuntu1.1 vim-runtime 2:8.0.1453-1ubuntu1.1 Ubuntu 16.04 LTS: vim 2:7.4.1689-3ubuntu1.3 vim-common 2:7.4.1689-3ubuntu1.3 vim-gui-common 2:7.4.1689-3ubuntu1.3 vim-runtime 2:7.4.1689-3ubuntu1.3 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4016-1

CVE-2017-5953, CVE-2019-12735

Severity
critical
Lowest
Low
Medium
High
Critical

June 11, 2019

Package Information

https://launchpad.net/ubuntu/+source/vim/2:8.1.0320-1ubuntu3.1 https://launchpad.net/ubuntu/+source/vim/2:8.0.1766-1ubuntu1.1 https://launchpad.net/ubuntu/+source/vim/2:8.0.1453-1ubuntu1.1 https://launchpad.net/ubuntu/+source/vim/2:7.4.1689-3ubuntu1.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here