Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Ubuntu 22.04 LTS USN-6195-1 Critical: Vim Denial Of Service Risks

Ubuntu Large Esm H500
Several security issues were fixed in Vim.
=========================================================================Ubuntu Security Notice USN-6195-1
July 03, 2023

vim vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in Vim.

Software Description:
- vim: Vi IMproved - enhanced vi editor

Details:

It was discovered that Vim contained an out-of-bounds read vulnerability.
An attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2022-0128)

It was discovered that Vim did not properly manage memory when freeing
allocated memory. An attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. (CVE-2022-0156)

It was discovered that Vim contained a heap-based buffer overflow
vulnerability. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. (CVE-2022-0158)

It was discovered that Vim did not properly manage memory when recording
and using select mode. An attacker could possibly use this issue to cause
a denial of service. (CVE-2022-0393)

It was discovered that Vim incorrectly handled certain memory operations
during a visual block yank. An attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. (CVE-2022-0407)

It was discovered that Vim contained a NULL pointer dereference
vulnerability when switching tabpages. An attacker could possible use this
issue to cause a denial of service. (CVE-2022-0696)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
   vim                             2:8.2.3995-1ubuntu2.9
   vim-athena                      2:8.2.3995-1ubuntu2.9
   vim-gtk3                        2:8.2.3995-1ubuntu2.9
   vim-nox                         2:8.2.3995-1ubuntu2.9
   vim-tiny                        2:8.2.3995-1ubuntu2.9
   xxd                             2:8.2.3995-1ubuntu2.9

In general, a standard system update will make all the necessary changes.

References:
   https://ubuntu.com/security/notices/USN-6195-1
   CVE-2022-0128, CVE-2022-0156, CVE-2022-0158, CVE-2022-0393,
   CVE-2022-0407, CVE-2022-0696

Package Information:
   https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.9

Ubuntu 22.04 LTS USN-6195-1 Critical: Vim Denial Of Service Risks

ubuntu
Calendar Grey July 3, 2023
Dist Ubuntu Esm H88
Ubuntu Security Notice USN-6195-1 highlights critical vulnerabilities in the Vim text editor, risking systems with significant issues such as unauthorized access and code execution
Several security issues were fixed in Vim.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: vim 2:8.2.3995-1ubuntu2.9 vim-athena 2:8.2.3995-1ubuntu2.9 vim-gtk3 2:8.2.3995-1ubuntu2.9 vim-nox 2:8.2.3995-1ubuntu2.9 vim-tiny 2:8.2.3995-1ubuntu2.9 xxd 2:8.2.3995-1ubuntu2.9 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6195-1

CVE-2022-0128, CVE-2022-0156, CVE-2022-0158, CVE-2022-0393,

CVE-2022-0407, CVE-2022-0696

Severity
critical
Lowest
Low
Medium
High
Critical

July 03, 2023

Package Information

https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.9

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here