| Summary: | vim new security issue CVE-2024-22667 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Nicolas Salguero <nicolas.salguero> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, marja11, sysadmin-bugs |
| Version: | 9 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UIQLVUSYHDN3644K6EFDI7PRZOTIKXM3/ | ||
| Whiteboard: | MGA9-64-OK | ||
| Source RPM: | vim-9.0.2130-2.mga9.src.rpm | CVE: | CVE-2024-22667 |
| Status comment: | |||
|
Description
Nicolas Salguero
2024-02-15 14:54:08 CET
Nicolas Salguero
2024-02-15 14:54:33 CET
Source RPM:
(none) =>
vim-9.0.2130-2.mga9.src.rpm Suggested advisory: ======================== The updated packages fix a security vulnerability: Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions. (CVE-2024-22667) References: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UIQLVUSYHDN3644K6EFDI7PRZOTIKXM3/ ======================== Updated packages in core/updates_testing: ======================== vim-common-9.1.111-1.mga9 vim-enhanced-9.1.111-1.mga9 vim-minimal-9.1.111-1.mga9 vim-X11-9.1.111-1.mga9 from SRPM: vim-9.1.111-1.mga9.src.rpm Assignee:
bugsquad =>
qa-bugs Tested in real hardware mageia 9 x86_64 Updated without issues Load a file add a line save the file load again the file the change done is there delete the line save the file cat the file Works Whiteboard:
(none) =>
MGA9-64-OK Validating. Keywords:
(none) =>
validated_update
Marja Van Waes
2024-02-16 22:08:27 CET
URL:
(none) =>
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UIQLVUSYHDN3644K6EFDI7PRZOTIKXM3/
Marja Van Waes
2024-02-16 22:10:37 CET
Keywords:
(none) =>
advisory An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2024-0040.html Status:
ASSIGNED =>
RESOLVED |