Bug 34057 - vim new security issue: potential code execution with tar.vim and special crafted tar files (CVE not assigned yet)
Summary: vim new security issue: potential code execution with tar.vim and special cra...
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-03-03 10:03 CET by Nicolas Salguero
Modified: 2025-03-06 18:57 CET (History)
3 users (show)

See Also:
Source RPM: vim-9.1.1122-1.mga9.src.rpm
CVE: CVE-2025-27423
Status comment:


Attachments

Description Nicolas Salguero 2025-03-03 10:03:46 CET
That issue was announced here:
https://www.openwall.com/lists/oss-security/2025/03/02/1
Nicolas Salguero 2025-03-03 10:05:29 CET

Whiteboard: (none) => MGA9TOO
Source RPM: (none) => vim-9.1.1122-1.mga9.src.rpm

Comment 1 Nicolas Salguero 2025-03-03 10:24:18 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Potential code execution with tar.vim and special crafted tar files.

References:
https://www.openwall.com/lists/oss-security/2025/03/02/1
========================

Updated packages in core/updates_testing:
========================
vim-X11-9.1.1166-1.mga9
vim-common-9.1.1166-1.mga9
vim-enhanced-9.1.1166-1.mga9
vim-minimal-9.1.1166-1.mga9

from SRPM:
vim-9.1.1166-1.mga9.src.rpm

Whiteboard: MGA9TOO => (none)
Severity: normal => major
Version: Cauldron => 9
Assignee: bugsquad => qa-bugs
Status: NEW => ASSIGNED

katnatek 2025-03-04 02:26:21 CET

CVE: (none) => CVE-2025-27423
Keywords: (none) => advisory

Comment 2 Herman Viaene 2025-03-04 10:50:54 CET
MGA9-64 Plasma Wayland on Compaq H000SB
No installation issues.
Used vim on a .txt file, applied commands dd, a, i and x. All worked OK.

Whiteboard: (none) => MGA9-64-OK
CC: (none) => herman.viaene

Comment 3 Thomas Andrews 2025-03-04 17:09:43 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 4 Mageia Robot 2025-03-06 18:57:51 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0089.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.