Security fix for CVE-2023-0049. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-0f6a9433cf 2023-01-11 01:20:34.979975 --------------------------------------------------------------------------------Name : vim Product : Fedora 37 Version : 9.0.1160 Release : 1.fc37 URL : https://www.vim.org/ Summary : The VIM editor Description : VIM (VIsual editor iMproved) is an updated and improved version of the vi editor. Vi was the first real screen-based editor for UNIX, and is still very popular. VIM improves on vi by adding new features: multiple windows, multi-level undo, block highlighting and more. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2023-0049 --------------------------------------------------------------------------------ChangeLog: * Mon Jan 9 2023 Zdenek Dohnal - 2:9.0.1160-1 - patchlevel 1160 * Mon Jan 9 2023 Zdenek Dohnal - 2:9.0.1054-2 - FTBFS with new FORTIFY_SOURCE=3 - remove it since Vim wants level 1 --------------------------------------------------------------------------------References: [ 1 ] Bug #2158269 - CVE-2023-0049 vim: out-of-bounds read in function build_stl_str_hl https://bugzilla.redhat.com/show_bug.cgi?id=2158269 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-0f6a9433cf' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announcemailing list --
Moderate: vim security update. \{'type': 'Security', 'shortCode': 'RL', 'name': 'RLSA-2021:4517', 'synopsis': 'Moderate: vim security update', 'severity': 'Moderate', 'topic': 'An update for vim is now available for Rocky Linux 8.\nRocky Linux Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.', 'description': 'Vim (Vi IMproved) is an updated and improved version of the vi editor.\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\nAdditional Changes:\nFor detailed information on changes in this release, see the Rocky Linux 8.5 Release Notes linked from the References section.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['2004621', '2004728'], 'cves': ['Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-3778.json:::CVE-2021-3778', 'Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-3796.json:::CVE-2021-3796'], 'references': [], 'publishedAt': '2021-11-15T07:26:49.199766Z', 'rpms': ['vim-8.0.1763-16.el8.src.rpm', 'vim-common-8.0.1763-16.el8.aarch64.rpm', 'vim-common-8.0.1763-16.el8.x86_64.rpm', 'vim-common-debuginfo-8.0.1763-16.el8.aarch64.rpm', 'vim-common-debuginfo-8.0.1763-16.el8.x86_64.rpm', 'vim-debuginfo-8.0.1763-16.el8.aarch64.rpm', 'vim-debuginfo-8.0.1763-16.el8.x86_64.rpm', 'vim-debugsource-8.0.1763-16.el8.aarch64.rpm', 'vim-debugsource-8.0.1763-16.el8.x86_64.rpm', 'vim-enhanced-8.0.1763-16.el8.aarch64.rpm', 'vim-enhanced-8.0.1763-16.el8.x86_64.rpm', 'vim-enhanced-debuginfo-8.0.1763-16.el8.aarch64.rpm', 'vim-enhanced-debuginfo-8.0.1763-16.el8.x86_64.rpm', 'vim-filesystem-8.0.1763-16.el8.noarch.rpm', 'vim-minimal-8.0.1763-16.el8.aarch64.rpm', 'vim-minimal-8.0.1763-16.el8.x86_64.rpm','vim-minimal-debuginfo-8.0.1763-16.el8.aarch64.rpm', 'vim-minimal-debuginfo-8.0.1763-16.el8.x86_64.rpm', 'vim-X11-8.0.1763-16.el8.aarch64.rpm', 'vim-X11-8.0.1763-16.el8.x86_64.rpm', 'vim-X11-debuginfo-8.0.1763-16.el8.aarch64.rpm', 'vim-X11-debuginfo-8.0.1763-16.el8.x86_64.rpm']}\. A timely patch for the emacs editor resolves important vulnerabilities in Rocky Linux 8, preserving system security.. Rocky Linux Advisory,Vim Security Update,Moderate Threat Update. . LinuxSecurity.com Team
Moderate: vim security update. \{'type': 'Security', 'shortCode': 'RL', 'name': 'RLSA-2022:366', 'synopsis': 'Moderate: vim security update', 'severity': 'Moderate', 'topic': 'An update for vim is now available for Rocky Linux 8.\nRocky Linux Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.', 'description': 'Vim (Vi IMproved) is an updated and improved version of the vi editor.\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['2016056', '2028122', '2028212', '2039685', '2039687'], 'cves': ['Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-3984.json:::CVE-2021-3984', 'Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-4019.json:::CVE-2021-4019'], 'references': [], 'publishedAt': '2022-02-02T04:36:58.482714Z', 'rpms': ['vim-8.0.1763-16.el8_5.4.src.rpm', 'vim-common-8.0.1763-16.el8_5.4.aarch64.rpm', 'vim-common-8.0.1763-16.el8_5.4.x86_64.rpm', 'vim-common-debuginfo-8.0.1763-16.el8_5.4.aarch64.rpm', 'vim-common-debuginfo-8.0.1763-16.el8_5.4.x86_64.rpm', 'vim-debuginfo-8.0.1763-16.el8_5.4.aarch64.rpm', 'vim-debuginfo-8.0.1763-16.el8_5.4.x86_64.rpm', 'vim-debugsource-8.0.1763-16.el8_5.4.aarch64.rpm', 'vim-debugsource-8.0.1763-16.el8_5.4.x86_64.rpm', 'vim-enhanced-8.0.1763-16.el8_5.4.aarch64.rpm', 'vim-enhanced-8.0.1763-16.el8_5.4.x86_64.rpm', 'vim-enhanced-debuginfo-8.0.1763-16.el8_5.4.aarch64.rpm', 'vim-enhanced-debuginfo-8.0.1763-16.el8_5.4.x86_64.rpm', 'vim-filesystem-8.0.1763-16.el8_5.4.noarch.rpm', 'vim-minimal-8.0.1763-16.el8_5.4.aarch64.rpm', 'vim-minimal-8.0.1763-16.el8_5.4.x86_64.rpm', 'vim-minimal-debuginfo-8.0.1763-16.el8_5.4.aarch64.rpm','vim-minimal-debuginfo-8.0.1763-16.el8_5.4.x86_64.rpm', 'vim-X11-8.0.1763-16.el8_5.4.aarch64.rpm', 'vim-X11-8.0.1763-16.el8_5.4.x86_64.rpm', 'vim-X11-debuginfo-8.0.1763-16.el8_5.4.aarch64.rpm', 'vim-X11-debuginfo-8.0.1763-16.el8_5.4.x86_64.rpm']}\. A crucial security patch released for Rocky Linux 8 addresses moderate severity vulnerabilities in Vim. Key information enclosed.. Vim Security Update, Rocky Linux Update, Moderate Severity Patch. . LinuxSecurity.com Team
This update removes the filemanager and _samples directories from the embedded FCKeditor, they contain code with know security vulnerabilities, even though that code couldn't be invoked when Moin was used with the default settings. Moin was probably not affected, but installing this update is still recommended as a security measure. CVE-2009-2265 is the related CVE identifier.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-7761 2009-07-19 03:26:20 -------------------------------------------------------------------------------- Name : moin Product : Fedora 10 Version : 1.6.4 Release : 3.fc10 URL : http://moinmo.in/ Summary : MoinMoin is a WikiEngine to collaborate on easily editable web pages Description : MoinMoin is an advanced, easy to use and extensible WikiEngine with a large community of users. Said in a few words, it is about collaboration on easily editable web pages. -------------------------------------------------------------------------------- Update Information: This update removes the filemanager and _samples directories from the embedded FCKeditor, they contain code with know security vulnerabilities, even though that code couldn't be invoked when Moin was used with the default settings. Moin was probably not affected, but installing this update is still recommended as a security measure. CVE-2009-2265 is the related CVE identifier. -------------------------------------------------------------------------------- ChangeLog: * Sun Jul 12 2009 Ville-Pekka Vainio 1.6.4-3 - Remove the filemanager and _samples directories from the embedded FCKeditor, they contain code with know security vulnerabilities, even though that code probably couldn't be invoked when moin was used with the default settings. - Fixes rhbz #509924, related to CVE-2009-2265 * Sat Jun 13 2009 Ville-Pekka Vainio 1.6.4-2 - Hierarchical ACL security fix from 1.8.4, 1.8 HG 897cdbe9e8f2 - Details athttp://moinmo.in/SecurityFixes#moin_1.8.3 - Convert CHANGES to UTF-8 * Mon Apr 20 2009 Ville-Pekka Vainio 1.6.4-1 - Update to 1.6.4 - CVE-2008-3381 fixed upstream - Re-fix CVE-2008-0781, upstream seems to have dropped the fix in 1.6, used part of upstream 1.5 db212dfc58ef, backported upstream 1.7 5f51246a4df1 and 269a1fbc3ed7 - Fix CVE-2009-0260, patch from Debian etch - Fix CVE-2009-0312 - Fix AttachFile escaping problems, backported upstream 1.7 5c4043e651b3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #509924 - CVE-2009-2265 moin: embedded fckeditor multiple directory traversal vulns https://bugzilla.redhat.com/show_bug.cgi?id=509924 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update moin' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.