Описание
Security update for vim
This update for vim fixes the following issues:
- CVE-2017-5953: Fixed a possible overflow with corrupted spell file (bsc#1024724)
Список пакетов
openSUSE Leap 42.1
gvim-7.4.326-11.1
vim-7.4.326-11.1
vim-data-7.4.326-11.1
Ссылки
- E-Mail link for openSUSE-SU-2017:0511-1
- SUSE Security Ratings
Описание
vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer overflow.
Затронутые продукты
openSUSE Leap 42.1:gvim-7.4.326-11.1
openSUSE Leap 42.1:vim-7.4.326-11.1
openSUSE Leap 42.1:vim-data-7.4.326-11.1
Ссылки
- CVE-2017-5953
- SUSE Bug 1024724
- SUSE Bug 1123143
- SUSE Bug 1173534