SUSE-SU-2024:0783-1
Dashboard / Vulnerabilities / SUSE-SU-2024:0783-1
SUSE-SU-2024:0783-1
Summary: Security update for vim
Details: This update for vim fixes the following issues: - CVE-2023-48231: Fixed Use-After-Free in win_close() (bsc#1217316). - CVE-2023-48232: Fixed Floating point Exception in adjust_plines_for_skipcol() (bsc#1217320). - CVE-2023-48233: Fixed overflow with count for :s command (bsc#1217321). - CVE-2023-48234: Fixed overflow in nv_z_get_count (bsc#1217324). - CVE-2023-48235: Fixed overflow in ex address parsing (bsc#1217326). - CVE-2023-48236: Fixed overflow in get_number (bsc#1217329). - CVE-2023-48237: Fixed overflow in shift_line (bsc#1217330). - CVE-2023-48706: Fixed heap-use-after-free in ex_substitute (bsc#1217432). - CVE-2024-22667: Fixed stack-based buffer overflow in did_set_langmap function in map.c (bsc#1219581). - CVE-2023-4750: Fixed heap use-after-free in function bt_quickfix (bsc#1215005). Updated to version 9.1 with patch level 0111: https://github.com/vim/vim/compare/v9.0.2103...v9.1.0111
References: https://www.suse.com/support/update/announcement/2024/suse-su-20240783-1/, https://bugzilla.suse.com/1215005, https://bugzilla.suse.com/1217316, https://bugzilla.suse.com/1217320, https://bugzilla.suse.com/1217321, https://bugzilla.suse.com/1217324, https://bugzilla.suse.com/1217326, https://bugzilla.suse.com/1217329, https://bugzilla.suse.com/1217330, https://bugzilla.suse.com/1217432, https://bugzilla.suse.com/1219581, https://www.suse.com/security/cve/CVE-2023-4750, https://www.suse.com/security/cve/CVE-2023-48231, https://www.suse.com/security/cve/CVE-2023-48232, https://www.suse.com/security/cve/CVE-2023-48233, https://www.suse.com/security/cve/CVE-2023-48234, https://www.suse.com/security/cve/CVE-2023-48235, https://www.suse.com/security/cve/CVE-2023-48236, https://www.suse.com/security/cve/CVE-2023-48237, https://www.suse.com/security/cve/CVE-2023-48706, https://www.suse.com/security/cve/CVE-2024-22667
Affected packages
Package
Name: vim
Purl: pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
