Advisories ยป MGASA-2022-0223

Updated vim packages fix security vulnerability

Publication date: 09 Jun 2022
Modification date: 09 Jun 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-1851 , CVE-2022-1886 , CVE-2022-1897 , CVE-2022-1898 , CVE-2022-1927 , CVE-2022-1942

Description

out-of-bounds read in gchar_cursor() in misc1.c (CVE-2022-1851)
use-after-free in find_pattern_in_path() in search.c (CVE-2022-1898)
out-of-bounds write in vim_regsub_both() in regexp.c (CVE-2022-1897)
buffer over-read in utf_ptr2char() in mbyte.c (CVE-2022-1927 )
out of bounds write in vim_regsub_both() (CVE-2022-1942)
heap-based buffer overflow in function utf_head_off (CVE-2022-1886)
                

References

SRPMS

8/core