Bug 32850

Summary: vim new security issue CVE-2024-22667
Product: Mageia Reporter: Nicolas Salguero <nicolas.salguero>
Component: SecurityAssignee: QA Team <qa-bugs>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: andrewsfarm, marja11, sysadmin-bugs
Version: 9Keywords: advisory, validated_update
Target Milestone: ---   
Hardware: All   
OS: Linux   
URL: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UIQLVUSYHDN3644K6EFDI7PRZOTIKXM3/
Whiteboard: MGA9-64-OK
Source RPM: vim-9.0.2130-2.mga9.src.rpm CVE: CVE-2024-22667
Status comment:

Nicolas Salguero 2024-02-15 14:54:33 CET

Source RPM: (none) => vim-9.0.2130-2.mga9.src.rpm
CVE: (none) => CVE-2024-22667

Comment 1 Nicolas Salguero 2024-02-15 15:26:55 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions. (CVE-2024-22667)

References:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UIQLVUSYHDN3644K6EFDI7PRZOTIKXM3/
========================

Updated packages in core/updates_testing:
========================
vim-common-9.1.111-1.mga9
vim-enhanced-9.1.111-1.mga9
vim-minimal-9.1.111-1.mga9
vim-X11-9.1.111-1.mga9

from SRPM:
vim-9.1.111-1.mga9.src.rpm

Assignee: bugsquad => qa-bugs
Status: NEW => ASSIGNED

Comment 2 katnatek 2024-02-16 03:35:32 CET
Tested in real hardware mageia 9 x86_64
Updated without issues
Load a file 
add a line
save the file
load again the file the change done is there
delete the line
save the file
cat the file

Works

Whiteboard: (none) => MGA9-64-OK

Comment 3 Thomas Andrews 2024-02-16 18:40:45 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Marja Van Waes 2024-02-16 22:08:27 CET

URL: (none) => https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UIQLVUSYHDN3644K6EFDI7PRZOTIKXM3/
CC: (none) => marja11

Marja Van Waes 2024-02-16 22:10:37 CET

Keywords: (none) => advisory

Comment 4 Mageia Robot 2024-02-17 01:56:19 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2024-0040.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED