CLSA-2022-1658172267
Dashboard / Vulnerabilities / CLSA-2022-1658172267
CLSA-2022-1658172267
Summary: Fix CVE(s): CVE-2022-2206, CVE-2022-2257, CVE-2022-2286, CVE-2022-2285, CVE-2022-2284, CVE-2022-2287, CVE-2022-2264
Details: * SECURITY UPDATE: Out-of-bound read in function msg_outtrans_attr - debian/patches/CVE-2022-2206.patch: Adjust cmdline_row and msg_row to the value of Rows. - CVE-2022-2206 * SECURITY UPDATE: Heap-based buffer overflow in function utfc_ptr2len - debian/patches/CVE-2022-2284.patch: Stop Visual mode when closing a window. - CVE-2022-2284 * SECURITY UPDATE: Integer overflow in function del_typebuf - debian/patches/CVE-2022-2285.patch: Put a NUL after the typeahead - CVE-2022-2285 * SECURITY UPDATE: Out-of-bounds read in function ins_bytes - debian/patches/CVE-2022-2286.patch: Check the length of the string - CVE-2022-2286 * SECURITY UPDATE: Out-of-bound read data in function suggest_trie_walk() abusing array byts - debian/patches/CVE-2022-2287.patch: Disallow adding a word with control characters or a trailing slash. - CVE-2022-2287 * SECURITY UPDATE: Heap-based buffer overflow in function inc on put command - debian/patches/CVE-2022-2264.patch: Adjust the end mark position. - CVE-2022-2264 * SECURITY UPDATE: Out-of-bound read in function msg_outtrans_special - debian/patches/CVE-2022-2257.patch: check for NUL in str2special - CVE-2022-2257
Affected packages
Package
Name: vim
Purl: pkg:deb/tuxcare/vim?distro=ubuntu-16.04
Affected ranges
Type: ECOSYSTEM
Events:
