Bug 29856 - vim new security issues CVE-2021-4136, CVE-2021-4166, CVE-2021-4173, CVE-2021-4187, CVE-2021-419[23], CVE-2021-46059
Summary: vim new security issues CVE-2021-4136, CVE-2021-4166, CVE-2021-4173, CVE-2021...
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-01-07 19:14 CET by David Walser
Modified: 2022-01-15 16:55 CET (History)
5 users (show)

See Also:
Source RPM: vim-8.2.3755-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2022-01-07 19:14:36 CET
Fedora has issued an advisory today (January 7):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/2EY2VFBU3YGGWI5BW4XKT3F37MYGEQUD/

The issues are fixed upstream in vim 8.2.3923.
David Walser 2022-01-07 19:14:46 CET

Status comment: (none) => Fixed upstream in vim 8.2.3923

Comment 1 Nicolas Lécureuil 2022-01-08 23:35:52 CET
fixed in mga8

src:
    - vim-8.2.4006-1.mga8

Status comment: Fixed upstream in vim 8.2.3923 => (none)
Assignee: bugsquad => qa-bugs
CC: (none) => mageia

Comment 2 David Walser 2022-01-09 00:01:54 CET
vim-X11-8.2.4006-1.mga8
vim-enhanced-8.2.4006-1.mga8
vim-minimal-8.2.4006-1.mga8
vim-common-8.2.4006-1.mga8

from vim-8.2.4006-1.mga8.src.rpm
Comment 3 Len Lawrence 2022-01-10 00:36:28 CET
mga8, x64
vim has been in use here on and off.  Updated the four packages.

Edited copies of a few ruby files.
Syntax highlighting works.  Checked insert and command modes.
Tried various commands like i,a,b,shift-l,r,x,d,p,Ctrl-h.
Multiple undos work fine (u in command mode, default mode backwards, Ctrl-R to move forwards again).
:wq to save and quit.

Restarted on same file.
Changed a character and quit without saving. :q!

Restarted on same file.
Inserted a word and tried to quit without saving.  :q
"E37: No write since last change (add ! to override)"

:help vi_diff.txt split the window horizontally and presented the required help in the upper panel.  Skimmed through it - there is a lot to read.  :exit to remove help window.

Leaving it there.  No apparent regressions.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => tarazed25

Comment 4 Len Lawrence 2022-01-10 00:47:38 CET
Should have tried some of the related commands.
view works, displaying the text in readonly mode.
No evim.  gvim seems to be the same as vim apart from reversing the foreground/background colours.
rvim launches but gives errors on a plain text file - no idea about that one.
ex starts in Ex mode, whatever that is - the text is invisible but :visual resumes normal mode.
Esoterica for most of us probably.
Comment 5 Thomas Andrews 2022-01-11 22:58:43 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Dave Hodgins 2022-01-14 22:42:40 CET

Keywords: (none) => advisory
Summary: vim new security issues CVE-2021-4136, CVE-2021-4166, CVE-2021-4173, CVE-2021-4186 => vim new security issues CVE-2021-4136, CVE-2021-4166, CVE-2021-4173, CVE-2021-4187
CC: (none) => davidwhodgins

Comment 6 David Walser 2022-01-15 00:59:33 CET
This update also fixes CVE-2021-46059:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/HD5S2FC2HF22A7XQXK2XXIR46EARVWIM/

Keywords: advisory => (none)
Summary: vim new security issues CVE-2021-4136, CVE-2021-4166, CVE-2021-4173, CVE-2021-4187 => vim new security issues CVE-2021-4136, CVE-2021-4166, CVE-2021-4173, CVE-2021-4187, CVE-2021-46059

Comment 7 Mageia Robot 2022-01-15 09:11:19 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0015.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED

Comment 8 David Walser 2022-01-15 16:55:47 CET
Two more CVEs fixed in this update...

CVE-2021-4193 	vim is vulnerable to Out-of-bounds Read
8.2.3950
https://bugzilla.redhat.com/show_bug.cgi?id=2039687

CVE-2021-4192 	vim is vulnerable to Use After Free
8.2.3949
https://bugzilla.redhat.com/show_bug.cgi?id=2039685

Summary: vim new security issues CVE-2021-4136, CVE-2021-4166, CVE-2021-4173, CVE-2021-4187, CVE-2021-46059 => vim new security issues CVE-2021-4136, CVE-2021-4166, CVE-2021-4173, CVE-2021-4187, CVE-2021-419[23], CVE-2021-46059
Keywords: (none) => advisory


Note You need to log in before you can comment on or make changes to this bug.