SUSE-SU-2023:3942-1
Dashboard / Vulnerabilities / SUSE-SU-2023:3942-1
SUSE-SU-2023:3942-1
Summary: Security update for vim
Details: This update for vim fixes the following issues: Security fixes: - CVE-2023-4733: Fixed use-after-free in function buflist_altfpos (bsc#1215004). - CVE-2023-4734: Fixed segmentation fault in function f_fullcommand (bsc#1214925). - CVE-2023-4735: Fixed out of bounds write in ops.c (bsc#1214924). - CVE-2023-4738: Fixed heap buffer overflow in vim_regsub_both (bsc#1214922). - CVE-2023-4752: Fixed heap use-after-free in function ins_compl_get_exp (bsc#1215006). - CVE-2023-4781: Fixed heap buffer overflow in function vim_regsub_both (bsc#1215033). Other fixes: - Calling vim on xterm leads to missing first character of the command prompt (bsc#1211461) - Rendering corruption in gvim with all 9.x versions (bsc#1210738) - Updated to version 9.0 with patch level 1894
References: https://www.suse.com/support/update/announcement/2023/suse-su-20233942-1/, https://bugzilla.suse.com/1210738, https://bugzilla.suse.com/1211461, https://bugzilla.suse.com/1214922, https://bugzilla.suse.com/1214924, https://bugzilla.suse.com/1214925, https://bugzilla.suse.com/1215004, https://bugzilla.suse.com/1215006, https://bugzilla.suse.com/1215033, https://www.suse.com/security/cve/CVE-2023-4733, https://www.suse.com/security/cve/CVE-2023-4734, https://www.suse.com/security/cve/CVE-2023-4735, https://www.suse.com/security/cve/CVE-2023-4738, https://www.suse.com/security/cve/CVE-2023-4752, https://www.suse.com/security/cve/CVE-2023-4781
Affected packages
Package
Name: vim
Purl: pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
