[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 850-1] vim security update



Package        : vim
Version        : 2:7.3.547-7+deb7u3
CVE ID         : CVE-2017-6349 CVE-2017-6350
Debian Bug     : #856266


Brief introduction 

CVE-2017-6349

    An integer overflow at a u_read_undo memory allocation site would occur
    for vim before patch 8.0.0377, if it does not properly validate values
    for tree length when reading a corrupted undo file, which may lead to
    resultant buffer overflows.

CVE-2017-6350

    An integer overflow at an unserialize_uep memory allocation site would
    occur for vim before patch 8.0.0378, if it does not properly validate
    values for tree length when reading a corrupted undo file, which may
    lead to resultant buffer overflows.

For Debian 7 "Wheezy", these problems have been fixed in version
2:7.3.547-7+deb7u3.

We recommend that you upgrade your vim packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-- 
James
GPG Key: 4096R/91BF BF4D 6956 BD5D F7B7  2D23 DFE6 91AE 331B A3DB

Attachment: signature.asc
Description: PGP signature


Reply to: