Package : vim
Version : 2:7.3.547-7+deb7u3
CVE ID : CVE-2017-6349 CVE-2017-6350
Debian Bug : #856266
Brief introduction
CVE-2017-6349
An integer overflow at a u_read_undo memory allocation site would occur
for vim before patch 8.0.0377, if it does not properly validate values
for tree length when reading a corrupted undo file, which may lead to
resultant buffer overflows.
CVE-2017-6350
An integer overflow at an unserialize_uep memory allocation site would
occur for vim before patch 8.0.0378, if it does not properly validate
values for tree length when reading a corrupted undo file, which may
lead to resultant buffer overflows.
For Debian 7 "Wheezy", these problems have been fixed in version
2:7.3.547-7+deb7u3.
We recommend that you upgrade your vim packages.
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
--
James
GPG Key: 4096R/91BF BF4D 6956 BD5D F7B7 2D23 DFE6 91AE 331B A3DB
Attachment:
signature.asc
Description: PGP signature