[CLSA-2022:1658853743] Fixed CVEs in vim: CVE-2022-2289, CVE-2022-2304
Type:
security
Severity:
Important
Release date:
2022-07-26
Description:
- CVE-2022-2289: bail out when diff pointer is no longer valid to avoid accessing freed memory with diff put - CVE-2022-2304: limit the word length to avoid out of bound accesing
Updated packages:
  • vim-common-7.4.629-5.2.el6.tuxcare.els23.x86_64.rpm
    sha:01bba3662d5e86f2dcfbe8a080dfef0e3fe27a45
  • vim-X11-7.4.629-5.2.el6.tuxcare.els23.x86_64.rpm
    sha:a35712587fbff30f694c6147b08328812b0583cf
  • vim-enhanced-7.4.629-5.2.el6.tuxcare.els23.x86_64.rpm
    sha:94a10cdf8e8a0c18355d07b3270496b0419f94e5
  • vim-minimal-7.4.629-5.2.el6.tuxcare.els23.x86_64.rpm
    sha:3fbc6863631ab462c60a921472414eb7187a5e77
  • vim-filesystem-7.4.629-5.2.el6.tuxcare.els23.x86_64.rpm
    sha:cd7b02601348ff6196e565443d2ce5260fcc14ae
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.