SUSE-SU-2022:3229-1
Dashboard / Vulnerabilities / SUSE-SU-2022:3229-1
SUSE-SU-2022:3229-1
Summary: Security update for vim
Details: This update for vim fixes the following issues: Updated to version 9.0 with patch level 0313: - CVE-2022-2183: Fixed out-of-bounds read through get_lisp_indent() (bsc#1200902). - CVE-2022-2182: Fixed heap-based buffer overflow through parse_cmd_address() (bsc#1200903). - CVE-2022-2175: Fixed buffer over-read through cmdline_insert_reg() (bsc#1200904). - CVE-2022-2304: Fixed stack buffer overflow in spell_dump_compl() (bsc#1201249). - CVE-2022-2343: Fixed heap-based buffer overflow in GitHub repository vim prior to 9.0.0044 (bsc#1201356). - CVE-2022-2344: Fixed another heap-based buffer overflow vim prior to 9.0.0045 (bsc#1201359). - CVE-2022-2345: Fixed use after free in GitHub repository vim prior to 9.0.0046. (bsc#1201363). - CVE-2022-2819: Fixed heap-based Buffer Overflow in compile_lock_unlock() (bsc#1202414). - CVE-2022-2874: Fixed NULL Pointer Dereference in generate_loadvar() (bsc#1202552). - CVE-2022-1968: Fixed use after free in utf_ptr2char (bsc#1200270). - CVE-2022-2124: Fixed out of bounds read in current_quote() (bsc#1200697). - CVE-2022-2125: Fixed out of bounds read in get_lisp_indent() (bsc#1200698). - CVE-2022-2126: Fixed out of bounds read in suggest_trie_walk() (bsc#1200700). - CVE-2022-2129: Fixed out of bounds write in vim_regsub_both() (bsc#1200701). - CVE-2022-1720: Fixed out of bounds read in grab_file_name() (bsc#1200732). - CVE-2022-2264: Fixed out of bounds read in inc() (bsc#1201132). - CVE-2022-2284: Fixed out of bounds read in utfc_ptr2len() (bsc#1201133). - CVE-2022-2285: Fixed negative size passed to memmove() due to integer overflow (bsc#1201134). - CVE-2022-2286: Fixed out of bounds read in ins_bytes() (bsc#1201135). - CVE-2022-2287: Fixed out of bounds read in suggest_trie_walk() (bsc#1201136). - CVE-2022-2231: Fixed null pointer dereference skipwhite() (bsc#1201150). - CVE-2022-2210: Fixed out of bounds read in ml_append_int() (bsc#1201151). - CVE-2022-2208: Fixed null pointer dereference in diff_check() (bsc#1201152). - CVE-2022-2207: Fixed out of bounds read in ins_bs() (bsc#1201153). - CVE-2022-2257: Fixed out of bounds read in msg_outtrans_special() (bsc#1201154). - CVE-2022-2206: Fixed out of bounds read in msg_outtrans_attr() (bsc#1201155). - CVE-2022-2522: Fixed out of bounds read via nested autocommand (bsc#1201863). - CVE-2022-2571: Fixed heap-based buffer overflow related to ins_comp_get_next_word_or_line() (bsc#1202046). - CVE-2022-2580: Fixed heap-based buffer overflow related to eval_string() (bsc#1202049). - CVE-2022-2581: Fixed out-of-bounds read related to cstrchr() (bsc#1202050). - CVE-2022-2598: Fixed undefined behavior for Input to API related to diff_mark_adjust_tp() and ex_diffgetput() (bsc#1202051). - CVE-2022-2817: Fixed use after gree in f_assert_fails() (bsc#1202420). - CVE-2022-2816: Fixed out-of-bounds Read in check_vim9_unlet() (bsc#1202421). - CVE-2022-2862: Fixed use-after-free in compile_nested_function() (bsc#1202511). - CVE-2022-2849: Fixed invalid memory access related to mb_ptr2len() (bsc#1202512). - CVE-2022-2845: Fixed buffer Over-read related to display_dollar() (bsc#1202515). - CVE-2022-2889: Fixed use-after-free in find_var_also_in_script() in evalvars.c (bsc#1202599). - CVE-2022-2923: Fixed NULL pointer dereference in GitHub repository vim/vim prior to 9.0.0240 (bsc#1202687). - CVE-2022-2946: Fixed use after free in function vim_vsnprintf_typval (bsc#1202689). - CVE-2022-3016: Fixed use after free in vim prior to 9.0.0285 (bsc#1202862). Bugfixes: - Fixing vim error on startup (bsc#1200884). - Fixing vim SUSE Linux Enterprise Server 15 SP4 Basesystem plugin-tlib issue (bsc#1201620).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20223229-1/, https://bugzilla.suse.com/1200270, https://bugzilla.suse.com/1200697, https://bugzilla.suse.com/1200698, https://bugzilla.suse.com/1200700, https://bugzilla.suse.com/1200701, https://bugzilla.suse.com/1200732, https://bugzilla.suse.com/1200884, https://bugzilla.suse.com/1200902, https://bugzilla.suse.com/1200903, https://bugzilla.suse.com/1200904, https://bugzilla.suse.com/1201132, https://bugzilla.suse.com/1201133, https://bugzilla.suse.com/1201134, https://bugzilla.suse.com/1201135, https://bugzilla.suse.com/1201136, https://bugzilla.suse.com/1201150, https://bugzilla.suse.com/1201151, https://bugzilla.suse.com/1201152, https://bugzilla.suse.com/1201153, https://bugzilla.suse.com/1201154, https://bugzilla.suse.com/1201155, https://bugzilla.suse.com/1201249, https://bugzilla.suse.com/1201356, https://bugzilla.suse.com/1201359, https://bugzilla.suse.com/1201363, https://bugzilla.suse.com/1201620, https://bugzilla.suse.com/1201863, https://bugzilla.suse.com/1202046, https://bugzilla.suse.com/1202049, https://bugzilla.suse.com/1202050, https://bugzilla.suse.com/1202051, https://bugzilla.suse.com/1202414, https://bugzilla.suse.com/1202420, https://bugzilla.suse.com/1202421, https://bugzilla.suse.com/1202511, https://bugzilla.suse.com/1202512, https://bugzilla.suse.com/1202515, https://bugzilla.suse.com/1202552, https://bugzilla.suse.com/1202599, https://bugzilla.suse.com/1202687, https://bugzilla.suse.com/1202689, https://bugzilla.suse.com/1202862, https://www.suse.com/security/cve/CVE-2022-1720, https://www.suse.com/security/cve/CVE-2022-1968, https://www.suse.com/security/cve/CVE-2022-2124, https://www.suse.com/security/cve/CVE-2022-2125, https://www.suse.com/security/cve/CVE-2022-2126, https://www.suse.com/security/cve/CVE-2022-2129, https://www.suse.com/security/cve/CVE-2022-2175, https://www.suse.com/security/cve/CVE-2022-2182, https://www.suse.com/security/cve/CVE-2022-2183, https://www.suse.com/security/cve/CVE-2022-2206, https://www.suse.com/security/cve/CVE-2022-2207, https://www.suse.com/security/cve/CVE-2022-2208, https://www.suse.com/security/cve/CVE-2022-2210, https://www.suse.com/security/cve/CVE-2022-2231, https://www.suse.com/security/cve/CVE-2022-2257, https://www.suse.com/security/cve/CVE-2022-2264, https://www.suse.com/security/cve/CVE-2022-2284, https://www.suse.com/security/cve/CVE-2022-2285, https://www.suse.com/security/cve/CVE-2022-2286, https://www.suse.com/security/cve/CVE-2022-2287, https://www.suse.com/security/cve/CVE-2022-2304, https://www.suse.com/security/cve/CVE-2022-2343, https://www.suse.com/security/cve/CVE-2022-2344, https://www.suse.com/security/cve/CVE-2022-2345, https://www.suse.com/security/cve/CVE-2022-2522, https://www.suse.com/security/cve/CVE-2022-2571, https://www.suse.com/security/cve/CVE-2022-2580, https://www.suse.com/security/cve/CVE-2022-2581, https://www.suse.com/security/cve/CVE-2022-2598, https://www.suse.com/security/cve/CVE-2022-2816, https://www.suse.com/security/cve/CVE-2022-2817, https://www.suse.com/security/cve/CVE-2022-2819, https://www.suse.com/security/cve/CVE-2022-2845, https://www.suse.com/security/cve/CVE-2022-2849, https://www.suse.com/security/cve/CVE-2022-2862, https://www.suse.com/security/cve/CVE-2022-2874, https://www.suse.com/security/cve/CVE-2022-2889, https://www.suse.com/security/cve/CVE-2022-2923, https://www.suse.com/security/cve/CVE-2022-2946, https://www.suse.com/security/cve/CVE-2022-3016
Affected packages
Package
Name: vim
Purl: pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
