vim-7.4.629-8.0.1.el7.AXS7
エラータID: AXSA:2024-8627:01
VIM (VIsual editor iMproved) is an updated and improved version of the vi
editor. Vi was the first real screen-based editor for UNIX, and is still very
popular. VIM improves on vi by adding new features: multiple windows,
multi-level undo, block highlighting and more.
Security Fix(es):
* CVE-2023-0054: check the return value of vim_regsub()
* CVE-2023-0049: avoid going over the NUL at the end
* CVE-2023-0288: prevent the cursor from moving to line zero
* CVE-2023-0433: check for not going over the end of the line
* CVE-2023-2610: limit the text length to MAXCOL
* CVE-2023-4750: check buffer is valid before accessing it
* CVE-2023-4733: verify oldwin pointer after reset_VIsual()
* CVE-2023-4751: stop Visual mode when using :ball
* CVE-2023-5344: add NULL at end of buffer
* CVE-2024-22667: pass size of errbuf down the call stack, use snprintf()
CVE(s):
CVE-2023-0049
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.
CVE-2023-0054
Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145.
CVE-2023-0288
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.
CVE-2023-0433
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.
CVE-2023-2610
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1532.
CVE-2023-4733
Use After Free in GitHub repository vim/vim prior to 9.0.1840.
CVE-2023-4750
Use After Free in GitHub repository vim/vim prior to 9.0.1857.
CVE-2023-4751
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.
CVE-2023-5344
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.
CVE-2024-22667
Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions.
Update packages.
Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions.
N/A
Asianux Server 7 for x86_64
- vim-common-7.4.629-8.0.1.el7.AXS7.x86_64.rpm
MD5: 795de1eb61ed41704dd47d1e74fcd86a
SHA-256: 0864891c99329847d7e69654c0aa48767df7af5828a7792b8c16e33c878abb09
Size: 5.92 MB - vim-enhanced-7.4.629-8.0.1.el7.AXS7.x86_64.rpm
MD5: 5ba190cef980821f808b5e51e6526e10
SHA-256: 9caefca2a0e8fafb40fab37b32bd3ca4a0ab10bca2069b9418103b9a3efd4dba
Size: 1.05 MB - vim-filesystem-7.4.629-8.0.1.el7.AXS7.x86_64.rpm
MD5: 6d74cedac08083d03fb54c1d0b835f2c
SHA-256: 00f95459927d59188db72ebef80c73d410deb267856025dc67e4b56398afbf3d
Size: 10.86 kB - vim-minimal-7.4.629-8.0.1.el7.AXS7.x86_64.rpm
MD5: 91284b74bc3a1cd27c12767ecf6c5154
SHA-256: 6222df8d4c5f1a02edf590819d570d9b2360f753f09dafdc24694d6d442213ed
Size: 443.09 kB - vim-X11-7.4.629-8.0.1.el7.AXS7.x86_64.rpm
MD5: 251bc56f102c33f6e96eeec5cd07271e
SHA-256: f587e7dfd4bea20bde4a984f44b227396e69f9a8313fd728dcdfc8dccaf09cd8
Size: 1.18 MB