Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

vim (Vi IMproved) : security update to 9.1.0404 #5897

Closed
MingcongBai opened this issue May 10, 2024 · 1 comment · Fixed by #6349
Closed

vim (Vi IMproved) : security update to 9.1.0404 #5897

MingcongBai opened this issue May 10, 2024 · 1 comment · Fixed by #6349
Labels
security Topic/issue involves a security issue/fixed upgrade Topic/issue involves a package upgrade

Comments

@MingcongBai
Copy link
Member

MingcongBai commented May 10, 2024

Affected package (and version)

vim <= 9.1.0403

CVE ID(s)

N/A

Severity

Low

Other security advisory ID(s)

N/A

Description/References

When outputting colored hexdumps using the -R command line flag,
together with -g1 (group every byte), -c 256 (format 256 octets per
line), -d (show offsets in decimal) and -o <large_numer> (add offset to
the file position), the buffer used to write to may overflow.

Impact is low since the user must intentionally execute xxd with several
non-default flags, but it may cause a crash of xxd.

Patch(es)/Solution(s)

Update.

@MingcongBai MingcongBai added upgrade Topic/issue involves a package upgrade security Topic/issue involves a security issue/fixed labels May 10, 2024
@MingcongBai
Copy link
Member Author

Not yet released at the time of writing.

@MingcongBai MingcongBai linked a pull request May 28, 2024 that will close this issue
7 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Topic/issue involves a security issue/fixed upgrade Topic/issue involves a package upgrade
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant