Release Info

Advisory: CLSA-2021:1639681859

OS: Ubuntu 16.04 ELS

Public date: 2021-12-16 00:00:00

Project: vim

Version: 3:7.4.1689-3ubuntu1.5+tuxcare.els3

Errata link: https://errata.cloudlinux.com/ubuntu16-els/CLSA-2021-1639681859.html

Changelog

* SECURITY UPDATE: Fix heap-based buffer overflow when reading character past end of line - debian/patches/CVE-2021-3927.patch: Correct the cursor column in src/ex_docmd.c. - CVE-2021-3927 * SECURITY UPDATE: Fix stack-based buffer overflow when reading uninitialized memory when giving spell suggestions - debian/patches/CVE-2021-3928.patch: Check that preword is not empty in src/spell.c. - CVE-2021-3928

Update

Packages list

vim_7.4.1689-3ubuntu1.5+tuxcare.els3_amd64.deb vim-athena_7.4.1689-3ubuntu1.5+tuxcare.els3_amd64.deb vim-athena-py2_7.4.1689-3ubuntu1.5+tuxcare.els3_amd64.deb vim-common_7.4.1689-3ubuntu1.5+tuxcare.els3_amd64.deb vim-doc_7.4.1689-3ubuntu1.5+tuxcare.els3_all.deb vim-gnome_7.4.1689-3ubuntu1.5+tuxcare.els3_amd64.deb vim-gnome-py2_7.4.1689-3ubuntu1.5+tuxcare.els3_amd64.deb vim-gtk_7.4.1689-3ubuntu1.5+tuxcare.els3_amd64.deb vim-gtk-py2_7.4.1689-3ubuntu1.5+tuxcare.els3_amd64.deb vim-gtk3_7.4.1689-3ubuntu1.5+tuxcare.els3_amd64.deb vim-gtk3-py2_7.4.1689-3ubuntu1.5+tuxcare.els3_amd64.deb vim-gui-common_7.4.1689-3ubuntu1.5+tuxcare.els3_all.deb vim-nox_7.4.1689-3ubuntu1.5+tuxcare.els3_amd64.deb vim-nox-py2_7.4.1689-3ubuntu1.5+tuxcare.els3_amd64.deb vim-runtime_7.4.1689-3ubuntu1.5+tuxcare.els3_all.deb vim-tiny_7.4.1689-3ubuntu1.5+tuxcare.els3_amd64.deb

CVEs

CVE-2021-3928
CVE-2021-3927