Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:02228-1

Опубликовано: 04 июл. 2025
Источник: suse-cvrf

Описание

Security update for vim

This update for vim fixes the following issues:

  • CVE-2024-41965: Fixed improper neutralization of argument delimiters in zip.vim that could have led to data loss (bsc#1228776).
  • CVE-2025-29768: Fixed double-free in dialog_changed() (bsc#1239602).

Список пакетов

Container suse/sle-micro-rancher/5.2:latest
vim-data-common-9.1.1406-150000.5.75.1
vim-small-9.1.1406-150000.5.75.1
Container suse/sle-micro-rancher/5.3:latest
vim-data-common-9.1.1406-150000.5.75.1
vim-small-9.1.1406-150000.5.75.1
Container suse/sle-micro-rancher/5.4:latest
vim-data-common-9.1.1406-150000.5.75.1
vim-small-9.1.1406-150000.5.75.1
Container suse/sle-micro/5.1/toolbox:latest
vim-9.1.1406-150000.5.75.1
vim-data-common-9.1.1406-150000.5.75.1
xxd-9.1.1406-150000.5.75.1
Container suse/sle-micro/5.2/toolbox:latest
vim-9.1.1406-150000.5.75.1
vim-data-common-9.1.1406-150000.5.75.1
xxd-9.1.1406-150000.5.75.1
Container suse/sle-micro/5.3/toolbox:latest
vim-9.1.1406-150000.5.75.1
vim-data-common-9.1.1406-150000.5.75.1
xxd-9.1.1406-150000.5.75.1
Container suse/sle-micro/5.4/toolbox:latest
vim-9.1.1406-150000.5.75.1
vim-data-common-9.1.1406-150000.5.75.1
xxd-9.1.1406-150000.5.75.1
SUSE Enterprise Storage 7.1
gvim-9.1.1406-150000.5.75.1
vim-9.1.1406-150000.5.75.1
vim-data-9.1.1406-150000.5.75.1
vim-data-common-9.1.1406-150000.5.75.1
vim-small-9.1.1406-150000.5.75.1
xxd-9.1.1406-150000.5.75.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
gvim-9.1.1406-150000.5.75.1
vim-9.1.1406-150000.5.75.1
vim-data-9.1.1406-150000.5.75.1
vim-data-common-9.1.1406-150000.5.75.1
vim-small-9.1.1406-150000.5.75.1
xxd-9.1.1406-150000.5.75.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
gvim-9.1.1406-150000.5.75.1
vim-9.1.1406-150000.5.75.1
vim-data-9.1.1406-150000.5.75.1
vim-data-common-9.1.1406-150000.5.75.1
vim-small-9.1.1406-150000.5.75.1
xxd-9.1.1406-150000.5.75.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
gvim-9.1.1406-150000.5.75.1
vim-9.1.1406-150000.5.75.1
vim-data-9.1.1406-150000.5.75.1
vim-data-common-9.1.1406-150000.5.75.1
vim-small-9.1.1406-150000.5.75.1
xxd-9.1.1406-150000.5.75.1
SUSE Linux Enterprise Micro 5.1
vim-data-common-9.1.1406-150000.5.75.1
vim-small-9.1.1406-150000.5.75.1
xxd-9.1.1406-150000.5.75.1
SUSE Linux Enterprise Micro 5.2
vim-data-common-9.1.1406-150000.5.75.1
vim-small-9.1.1406-150000.5.75.1
xxd-9.1.1406-150000.5.75.1
SUSE Linux Enterprise Micro 5.3
vim-data-common-9.1.1406-150000.5.75.1
vim-small-9.1.1406-150000.5.75.1
xxd-9.1.1406-150000.5.75.1
SUSE Linux Enterprise Micro 5.4
vim-data-common-9.1.1406-150000.5.75.1
vim-small-9.1.1406-150000.5.75.1
xxd-9.1.1406-150000.5.75.1
SUSE Linux Enterprise Server 15 SP3-LTSS
gvim-9.1.1406-150000.5.75.1
vim-9.1.1406-150000.5.75.1
vim-data-9.1.1406-150000.5.75.1
vim-data-common-9.1.1406-150000.5.75.1
vim-small-9.1.1406-150000.5.75.1
xxd-9.1.1406-150000.5.75.1
SUSE Linux Enterprise Server 15 SP4-LTSS
gvim-9.1.1406-150000.5.75.1
vim-9.1.1406-150000.5.75.1
vim-data-9.1.1406-150000.5.75.1
vim-data-common-9.1.1406-150000.5.75.1
vim-small-9.1.1406-150000.5.75.1
xxd-9.1.1406-150000.5.75.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
gvim-9.1.1406-150000.5.75.1
vim-9.1.1406-150000.5.75.1
vim-data-9.1.1406-150000.5.75.1
vim-data-common-9.1.1406-150000.5.75.1
vim-small-9.1.1406-150000.5.75.1
xxd-9.1.1406-150000.5.75.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
gvim-9.1.1406-150000.5.75.1
vim-9.1.1406-150000.5.75.1
vim-data-9.1.1406-150000.5.75.1
vim-data-common-9.1.1406-150000.5.75.1
vim-small-9.1.1406-150000.5.75.1
xxd-9.1.1406-150000.5.75.1
SUSE Manager Proxy 4.3
vim-9.1.1406-150000.5.75.1
vim-data-9.1.1406-150000.5.75.1
vim-data-common-9.1.1406-150000.5.75.1
vim-small-9.1.1406-150000.5.75.1
xxd-9.1.1406-150000.5.75.1
SUSE Manager Server 4.3
vim-9.1.1406-150000.5.75.1
vim-data-9.1.1406-150000.5.75.1
vim-data-common-9.1.1406-150000.5.75.1
vim-small-9.1.1406-150000.5.75.1
xxd-9.1.1406-150000.5.75.1

Описание

Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a buffer, Vim may ask the user what to do with the modified buffer. If the user wants the changed buffer to be saved, Vim may create a new Untitled file, if the buffer did not have a name yet. However, when setting the buffer name to Unnamed, Vim will falsely free a pointer twice, leading to a double-free and possibly later to a heap-use-after-free, which can lead to a crash. The issue has been fixed as of Vim patch v9.1.0648.


Затронутые продукты
Container suse/sle-micro-rancher/5.2:latest:vim-data-common-9.1.1406-150000.5.75.1
Container suse/sle-micro-rancher/5.2:latest:vim-small-9.1.1406-150000.5.75.1
Container suse/sle-micro-rancher/5.3:latest:vim-data-common-9.1.1406-150000.5.75.1
Container suse/sle-micro-rancher/5.3:latest:vim-small-9.1.1406-150000.5.75.1

Ссылки

Описание

Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with Vim and then press 'x' on such a strange filename. The issue has been fixed as of Vim patch v9.1.1198.


Затронутые продукты
Container suse/sle-micro-rancher/5.2:latest:vim-data-common-9.1.1406-150000.5.75.1
Container suse/sle-micro-rancher/5.2:latest:vim-small-9.1.1406-150000.5.75.1
Container suse/sle-micro-rancher/5.3:latest:vim-data-common-9.1.1406-150000.5.75.1
Container suse/sle-micro-rancher/5.3:latest:vim-small-9.1.1406-150000.5.75.1

Ссылки
Уязвимость SUSE-SU-2025:02228-1