Bugzilla – Bug 1027057
VUL-1: CVE-2017-6349: vim: An integer overflow at a u_read_undo memory allocation site would occurfor vim before patch 8.0.037...
Last modified: 2019-06-14 06:41:07 UTC
CVE-2017-6349 An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows. MISC:https://github.com/vim/vim/commit/3eb1637b1bba19519885dd6d377bd5596e91d22c MISC:https://groups.google.com/forum/#!topic/vim_dev/LAgsTcdSfNA MISC:https://groups.google.com/forum/#!topic/vim_dev/QPZc0CY9j3Y
i cant spot the code in sle11 vim, it might just be in sle12 and opensuse vim
bugbot adjusting priority
SUSE-SU-2017:1712-1: An update that solves three vulnerabilities and has one errata is now available. Category: security (moderate) Bug References: 1018870,1024724,1027053,1027057 CVE References: CVE-2017-5953,CVE-2017-6349,CVE-2017-6350 Sources used: SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src): vim-7.4.326-16.1 SUSE Linux Enterprise Server 12-SP2 (src): vim-7.4.326-16.1 SUSE Linux Enterprise Desktop 12-SP2 (src): vim-7.4.326-16.1 OpenStack Cloud Magnum Orchestration 7 (src): vim-7.4.326-16.1
openSUSE-SU-2017:1811-1: An update that solves three vulnerabilities and has one errata is now available. Category: security (moderate) Bug References: 1018870,1024724,1027053,1027057 CVE References: CVE-2017-5953,CVE-2017-6349,CVE-2017-6350 Sources used: openSUSE Leap 42.2 (src): vim-7.4.326-10.3.1
Fixed.