SUSE-SU-2022:4282-1
Dashboard / Vulnerabilities / SUSE-SU-2022:4282-1
SUSE-SU-2022:4282-1
Summary: Security update for vim
Details: This update for vim fixes the following issues: Updated to version 9.0 with patch level 0814: - CVE-2021-3928: Fixed stack-based buffer overflow (bsc#1192478). - CVE-2022-3234: Fixed heap-based buffer overflow (bsc#1203508). - CVE-2022-3235: Fixed use-after-free (bsc#1203509). - CVE-2022-3324: Fixed stack-based buffer overflow (bsc#1203820). - CVE-2022-3705: Fixed use-after-free in function qf_update_buffer of the file quickfix.c (bsc#1204779). - CVE-2022-2982: Fixed use-after-free in qf_fill_buffer() (bsc#1203152). - CVE-2022-3296: Fixed stack out of bounds read in ex_finally() in ex_eval.c (bsc#1203796). - CVE-2022-3297: Fixed use-after-free in process_next_cpt_value() at insexpand.c (bsc#1203797). - CVE-2022-3099: Fixed use-after-free in ex_docmd.c (bsc#1203110). - CVE-2022-3134: Fixed use-after-free in do_tag() (bsc#1203194). - CVE-2022-3153: Fixed NULL pointer dereference (bsc#1203272). - CVE-2022-3278: Fixed NULL pointer dereference in eval_next_non_blank() in eval.c (bsc#1203799). - CVE-2022-3352: Fixed use-after-free (bsc#1203924). - CVE-2022-2980: Fixed NULL pointer dereference in do_mouse() (bsc#1203155). - CVE-2022-3037: Fixed use-after-free (bsc#1202962).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20224282-1/, https://bugzilla.suse.com/1192478, https://bugzilla.suse.com/1202962, https://bugzilla.suse.com/1203110, https://bugzilla.suse.com/1203152, https://bugzilla.suse.com/1203155, https://bugzilla.suse.com/1203194, https://bugzilla.suse.com/1203272, https://bugzilla.suse.com/1203508, https://bugzilla.suse.com/1203509, https://bugzilla.suse.com/1203796, https://bugzilla.suse.com/1203797, https://bugzilla.suse.com/1203799, https://bugzilla.suse.com/1203820, https://bugzilla.suse.com/1203924, https://bugzilla.suse.com/1204779, https://www.suse.com/security/cve/CVE-2021-3928, https://www.suse.com/security/cve/CVE-2022-2980, https://www.suse.com/security/cve/CVE-2022-2982, https://www.suse.com/security/cve/CVE-2022-3037, https://www.suse.com/security/cve/CVE-2022-3099, https://www.suse.com/security/cve/CVE-2022-3134, https://www.suse.com/security/cve/CVE-2022-3153, https://www.suse.com/security/cve/CVE-2022-3234, https://www.suse.com/security/cve/CVE-2022-3235, https://www.suse.com/security/cve/CVE-2022-3278, https://www.suse.com/security/cve/CVE-2022-3296, https://www.suse.com/security/cve/CVE-2022-3297, https://www.suse.com/security/cve/CVE-2022-3324, https://www.suse.com/security/cve/CVE-2022-3352, https://www.suse.com/security/cve/CVE-2022-3705
Affected packages
Package
Name: vim
Purl: pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Micro%205.3
Affected ranges
Type: ECOSYSTEM
Events:
