Bug 32850 - vim new security issue CVE-2024-22667
Summary: vim new security issue CVE-2024-22667
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: https://lists.fedoraproject.org/archi...
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2024-02-15 14:54 CET by Nicolas Salguero
Modified: 2024-02-17 01:56 CET (History)
3 users (show)

See Also:
Source RPM: vim-9.0.2130-2.mga9.src.rpm
CVE: CVE-2024-22667
Status comment:


Attachments

Nicolas Salguero 2024-02-15 14:54:33 CET

Source RPM: (none) => vim-9.0.2130-2.mga9.src.rpm
CVE: (none) => CVE-2024-22667

Comment 1 Nicolas Salguero 2024-02-15 15:26:55 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions. (CVE-2024-22667)

References:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UIQLVUSYHDN3644K6EFDI7PRZOTIKXM3/
========================

Updated packages in core/updates_testing:
========================
vim-common-9.1.111-1.mga9
vim-enhanced-9.1.111-1.mga9
vim-minimal-9.1.111-1.mga9
vim-X11-9.1.111-1.mga9

from SRPM:
vim-9.1.111-1.mga9.src.rpm

Assignee: bugsquad => qa-bugs
Status: NEW => ASSIGNED

Comment 2 katnatek 2024-02-16 03:35:32 CET
Tested in real hardware mageia 9 x86_64
Updated without issues
Load a file 
add a line
save the file
load again the file the change done is there
delete the line
save the file
cat the file

Works

Whiteboard: (none) => MGA9-64-OK

Comment 3 Thomas Andrews 2024-02-16 18:40:45 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Marja Van Waes 2024-02-16 22:08:27 CET

URL: (none) => https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UIQLVUSYHDN3644K6EFDI7PRZOTIKXM3/
CC: (none) => marja11

Marja Van Waes 2024-02-16 22:10:37 CET

Keywords: (none) => advisory

Comment 4 Mageia Robot 2024-02-17 01:56:19 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2024-0040.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.