FS#54773 - [vim] v8.0.0707 includes fixes for CVE-2017-11109

Attached to Project: Arch Linux
Opened by Jonathon (jonathon) - Wednesday, 12 July 2017, 09:45 GMT
Last edited by Levente Polyak (anthraxx) - Tuesday, 18 July 2017, 11:37 GMT
Task Type Bug Report
Category Security
Status Closed
Assigned To Anatol Pomozov (anatolik)
Architecture All
Severity High
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 1
Private No

Details

Description:

New upstream patch-releases include fixes for CVE-2017-11109. Package was marked out-of-date a month ago so raising a bug to get awareness of the new patches; please update the package to bring it up-to-date.

8.0.0703: Illegal memory access with empty :doau command
8.0.0706: Crash when cancelling the cmdline window in Ex mode
8.0.0707: Freeing wrong memory when manipulating buffers in autocommands

Additional info:

https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-11109
This task depends upon

Closed by  Levente Polyak (anthraxx)
Tuesday, 18 July 2017, 11:37 GMT
Reason for closing:  Fixed
Additional comments about closing:  8.0.0722-1

Loading...