[SECURITY] [DLA 3588-1] vim security update
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-3588-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Bastien Roucariès
September 29, 2023 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : vim
Version : 2:8.1.0875-5+deb10u6
CVE ID : CVE-2023-4752 CVE-2023-4781
Multiple vulnerabilities were found in vim a text editor.
CVE-2023-4752
A heap use after free was found in ins_compl_get_exp()
CVE-2023-4781
A heap-buffer-overflow was found in vim_regsub_both()
For Debian 10 buster, these problems have been fixed in version
2:8.1.0875-5+deb10u6.
We recommend that you upgrade your vim packages.
For the detailed security status of vim please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/vim
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmUW1qEACgkQADoaLapB
CF+r9w/6AhmvtjmugFANYuODCJ86S8FTewU8WL4Jh+MLp9rVfA00wAt4GmLn9Zfp
zrkIe4MOkESjTgJVE/wyAZJKckKXo8x3DKFfh5ONG0qmUBU+RowPK8osL+HhGeU5
GzCCAzQnzmptZfYk9wzTnhxXQ08q8jT9aceJ0y1g6lZWS6cfK2NqFYtrecz1Mvqi
8xOP9godr5SFW6C7R4sWQacWDbSn1fQtrMVFnTVa4+9E2GJdK2IuWtFfH1WDhBTe
FW0bK69VNInuXaEvrgfaY06G58qXX5dcQqtHm8EagE9pBRt+E7JbYwgvc5VrzTtl
zfEPYPis81NN2VbF6qWMqBZPO2GWJ7+RZk3dBU0GkUGEoMNv1H+bVqyQnrQ9dMWg
ZnDlb+ms0ytIoljm/s8b+GbVdQBAlONrOjzwpfkG72ELwsP/RkeLf9eQowxUqIyw
WZJWBp7GMJhvf2ptNcEmRJOR/vpP62DdXFBvph/xoUM+6VULC1jZt4NOy6SSnKkC
iItBosQgkTUvRNBK0vdT+EITo/thlzqFW8aCta6l5ThjB7fuoxpYfpQnJ6TZ+iIy
30TS831WCPbdTmcjeRlFv9UXSxmllZwIC3/YhPBCPreHnTrG7TvuxG/Edhh5iuYl
NW53WqzqKU83Tm84M6bQkcZns9YYZwPHZtuDf2g8JKAp47FDvjY=
=KTPm
-----END PGP SIGNATURE-----
Reply to: