CLSA-2022-1657182150
Dashboard / Vulnerabilities / CLSA-2022-1657182150
CLSA-2022-1657182150
Summary: Fix CVE(s): CVE-2022-2129, CVE-2022-2124, CVE-2022-2125, CVE-2022-2126, CVE-2022-1720
Details: * SECURITY UPDATE: Reading past end of line with "gf" in Visual block mode - debian/patches/CVE-2022-1720.patch: Do not include the NUL in the length - CVE-2022-1720 * SECURITY UPDATE: Searching for quotes may go over the end of the line - debian/patches/CVE-2022-2124.patch: Check for running into the NUL - CVE-2022-2124 * SECURITY UPDATE: Lisp indenting my run over the end of the line - debian/patches/CVE-2022-2125.patch: Check for NUL earlier - CVE-2022-2125 * SECURITY UPDATE: Using invalid index when looking for spell suggestions - debian/patches/CVE-2022-2126.patch: Do not decrement the index when it is zero - CVE-2022-2126 * SECURITY UPDATE: Substitute may overrun destination buffer - debian/patches/CVE-2022-2129.patch: Disallow switching buffers in a substitute expression - CVE-2022-2129
Affected packages
Package
Name: vim
Purl: pkg:deb/tuxcare/vim?distro=ubuntu-16.04
Affected ranges
Type: ECOSYSTEM
Events:
