Release Info

Advisory: CLSA-2022:1657182150

OS: Ubuntu 16.04 ELS

Public date: 2022-07-07 00:00:00

Project: vim

Version: 3:7.4.1689-3ubuntu1.5+tuxcare.els20

Errata link: https://errata.tuxcare.com/els_os/ubuntu16.04els/CLSA-2022-1657182150.html

Changelog

* SECURITY UPDATE: Reading past end of line with "gf" in Visual block mode - debian/patches/CVE-2022-1720.patch: Do not include the NUL in the length - CVE-2022-1720 * SECURITY UPDATE: Searching for quotes may go over the end of the line - debian/patches/CVE-2022-2124.patch: Check for running into the NUL - CVE-2022-2124 * SECURITY UPDATE: Lisp indenting my run over the end of the line - debian/patches/CVE-2022-2125.patch: Check for NUL earlier - CVE-2022-2125 * SECURITY UPDATE: Using invalid index when looking for spell suggestions - debian/patches/CVE-2022-2126.patch: Do not decrement the index when it is zero - CVE-2022-2126 * SECURITY UPDATE: Substitute may overrun destination buffer - debian/patches/CVE-2022-2129.patch: Disallow switching buffers in a substitute expression - CVE-2022-2129

Update

Update command: apt-get update apt-get --only-upgrade install vim*

Packages list

vim_7.4.1689-3ubuntu1.5+tuxcare.els20_amd64.deb vim-athena_7.4.1689-3ubuntu1.5+tuxcare.els20_amd64.deb vim-athena-py2_7.4.1689-3ubuntu1.5+tuxcare.els20_amd64.deb vim-common_7.4.1689-3ubuntu1.5+tuxcare.els20_amd64.deb vim-doc_7.4.1689-3ubuntu1.5+tuxcare.els20_all.deb vim-gnome_7.4.1689-3ubuntu1.5+tuxcare.els20_amd64.deb vim-gnome-py2_7.4.1689-3ubuntu1.5+tuxcare.els20_amd64.deb vim-gtk_7.4.1689-3ubuntu1.5+tuxcare.els20_amd64.deb vim-gtk-py2_7.4.1689-3ubuntu1.5+tuxcare.els20_amd64.deb vim-gtk3_7.4.1689-3ubuntu1.5+tuxcare.els20_amd64.deb vim-gtk3-py2_7.4.1689-3ubuntu1.5+tuxcare.els20_amd64.deb vim-gui-common_7.4.1689-3ubuntu1.5+tuxcare.els20_all.deb vim-nox_7.4.1689-3ubuntu1.5+tuxcare.els20_amd64.deb vim-nox-py2_7.4.1689-3ubuntu1.5+tuxcare.els20_amd64.deb vim-runtime_7.4.1689-3ubuntu1.5+tuxcare.els20_all.deb vim-tiny_7.4.1689-3ubuntu1.5+tuxcare.els20_amd64.deb

CVEs

CVE-2022-2125
CVE-2022-2126
CVE-2022-2129
CVE-2022-2124
CVE-2022-1720