[CLSA-2022:1658854080] Fixed CVEs in vim: CVE-2022-2289, CVE-2022-2304
Type:
security
Severity:
Important
Release date:
2022-07-26
Description:
- CVE-2022-2289: bail out when diff pointer is no longer valid to avoid accessing freed memory with diff put - CVE-2022-2304: limit the word length to avoid out of bound accesing
Updated packages:
  • vim-common-7.4.629-5.2.el6.tuxcare.els23.x86_64.rpm
    sha:a84eb1bca3789faac5cbf3b5e2ee174984941aaa
  • vim-filesystem-7.4.629-5.2.el6.tuxcare.els23.x86_64.rpm
    sha:2695dde4c86ec96cef1ef8ed84c1422bce895288
  • vim-minimal-7.4.629-5.2.el6.tuxcare.els23.x86_64.rpm
    sha:af7dc1c29b401f3956021715bd5ff4527d950ecb
  • vim-enhanced-7.4.629-5.2.el6.tuxcare.els23.x86_64.rpm
    sha:c01bb4a4585fa40b650b54ec807c4badb31672cc
  • vim-X11-7.4.629-5.2.el6.tuxcare.els23.x86_64.rpm
    sha:b363d476d06f13ee1a373510047261be72b5a8bd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.