SUSE-SU-2024:1287-1
Dashboard / Vulnerabilities / SUSE-SU-2024:1287-1
SUSE-SU-2024:1287-1
Summary: Security update for vim
Details: This update for vim fixes the following issues: Updated to version 9.1.0111, fixes the following security problems - CVE-2023-48231: Use-After-Free in win_close() (bsc#1217316). - CVE-2023-48232: Floating point Exception in adjust_plines_for_skipcol() (bsc#1217320). - CVE-2023-48233: overflow with count for :s command (bsc#1217321). - CVE-2023-48234: overflow in nv_z_get_count (bsc#1217324). - CVE-2023-48235: overflow in ex address parsing (CVE-2023-48235). - CVE-2023-48236: overflow in get_number (bsc#1217329). - CVE-2023-48237: overflow in shift_line (bsc#1217330). - CVE-2023-48706: heap-use-after-free in ex_substitute (bsc#1217432). - CVE-2024-22667: stack-based buffer overflow in did_set_langmap function in map.c (bsc#1219581). - CVE-2023-4750: Heap use-after-free in function bt_quickfix (bsc#1215005).
References: https://www.suse.com/support/update/announcement/2024/suse-su-20241287-1/, https://bugzilla.suse.com/1215005, https://bugzilla.suse.com/1217316, https://bugzilla.suse.com/1217320, https://bugzilla.suse.com/1217321, https://bugzilla.suse.com/1217324, https://bugzilla.suse.com/1217326, https://bugzilla.suse.com/1217329, https://bugzilla.suse.com/1217330, https://bugzilla.suse.com/1217432, https://bugzilla.suse.com/1219581, https://www.suse.com/security/cve/CVE-2023-4750, https://www.suse.com/security/cve/CVE-2023-48231, https://www.suse.com/security/cve/CVE-2023-48232, https://www.suse.com/security/cve/CVE-2023-48233, https://www.suse.com/security/cve/CVE-2023-48234, https://www.suse.com/security/cve/CVE-2023-48235, https://www.suse.com/security/cve/CVE-2023-48236, https://www.suse.com/security/cve/CVE-2023-48237, https://www.suse.com/security/cve/CVE-2023-48706, https://www.suse.com/security/cve/CVE-2024-22667
Affected packages
Package
Name: vim
Purl: pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Micro%205.5
Affected ranges
Type: ECOSYSTEM
Events:
