CLSA-2022-1659636773
Dashboard / Vulnerabilities / CLSA-2022-1659636773
CLSA-2022-1659636773
Summary: Fix CVE(s): CVE-2022-2344, CVE-2022-2345, CVE-2022-2522, CVE-2022-2343
Details: * SECURITY UPDATE: Using freed memory with recursive substitute - debian/patches/CVE-2022-2345.patch: Always make a copy for reg_prev_sub - CVE-2022-2345 * SECURITY UPDATE: Reading past end of completion with duplicate match - debian/patches/CVE-2022-2344.patch: Check string length - CVE-2022-2344 * SECURITY UPDATE: Reading past end of completion with a long line and 'infercase' set - debian/patches/CVE-2022-2343.patch: Allocate the string if needed - CVE-2022-2343 * SECURITY UPDATE: Accessing uninitialized memory when completing long line - debian/patches/CVE-2022-2522.patch: Terminate string with NUL. - CVE-2022-2522
Affected packages
Package
Name: vim
Purl: pkg:deb/tuxcare/vim?distro=ubuntu-16.04
Affected ranges
Type: ECOSYSTEM
Events:
