CLSA-2022-1653329020
Dashboard / Vulnerabilities / CLSA-2022-1653329020
CLSA-2022-1653329020
Summary: Fix CVE(s): CVE-2022-1629, CVE-2022-1616, CVE-2022-1620, CVE-2022-1621, CVE-2022-1619
Details: * SECURITY UPDATE: Going before the start of the command line - debian/patches/CVE-2022-1619.patch: Check already being at the start of the command line - CVE-2022-1619 * SECURITY UPDATE: NULL pointer access when using invalid pattern - debian/patches/CVE-2022-1620.patch: Check for failed regexp program - CVE-2022-1620 * SECURITY UPDATE: Can add invalid bytes with :spellgood - debian/patches/CVE-2022-1621.patch: Check for a valid word string - CVE-2022-1621 * SECURITY UPDATE: Trailing backslash may cause reading past end of line - debian/patches/CVE-2022-1629.patch: Check for NUL after backslash - CVE-2022-1629 * SECURITY UPDATE: Buffer overflow with invalid command with composing chars - debian/patches/CVE-2022-1616.patch: Check that the whole character fits in the buffer - CVE-2022-1616
Affected packages
Package
Name: vim
Purl: pkg:deb/tuxcare/vim?distro=ubuntu-16.04
Affected ranges
Type: ECOSYSTEM
Events:
