Bugzilla – Bug 1192478
VUL-0: CVE-2021-3928: vim: vim is vulnerable to Stack-based Buffer Overflow
Last modified: 2022-04-19 22:27:43 UTC
CVE-2021-3928 vim is vulnerable to Stack-based Buffer Overflow Upstream fix commit [0] [0] https://github.com/vim/vim/commit/15d9890eee53afc61eb0a03b878a19cb5672f732 References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-3928 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3928 https://github.com/vim/vim/commit/15d9890eee53afc61eb0a03b878a19cb5672f732 https://huntr.dev/bounties/29c3ebd2-d601-481c-bf96-76975369d0cd
Affected codestreams: - SUSE:Carwos:1 - SUSE:SLE-11:Update - SUSE:SLE-11-SP2:Update - SUSE:SLE-12:Update - SUSE:SLE-15:Update
The bug I could not reproduce with the 8.0 codebase from SLE15. But the patch in the upstream actually makes the code safer so it is ported. The next upcoming MU will contain the patch. If there is a need we may offer a PTF for customers who need it.
SUSE-SU-2022:0736-1: An update that fixes 14 vulnerabilities is now available. Category: security (important) Bug References: 1190533,1190570,1191893,1192478,1192481,1193294,1193298,1194216,1194556,1195004,1195066,1195126,1195202,1195356 CVE References: CVE-2021-3778,CVE-2021-3796,CVE-2021-3872,CVE-2021-3927,CVE-2021-3928,CVE-2021-3984,CVE-2021-4019,CVE-2021-4193,CVE-2021-46059,CVE-2022-0318,CVE-2022-0319,CVE-2022-0351,CVE-2022-0361,CVE-2022-0413 JIRA References: Sources used: SUSE Manager Server 4.1 (src): vim-8.0.1568-5.17.1 SUSE Manager Retail Branch Server 4.1 (src): vim-8.0.1568-5.17.1 SUSE Manager Proxy 4.1 (src): vim-8.0.1568-5.17.1 SUSE Linux Enterprise Server for SAP 15-SP2 (src): vim-8.0.1568-5.17.1 SUSE Linux Enterprise Server for SAP 15-SP1 (src): vim-8.0.1568-5.17.1 SUSE Linux Enterprise Server for SAP 15 (src): vim-8.0.1568-5.17.1 SUSE Linux Enterprise Server 15-SP2-LTSS (src): vim-8.0.1568-5.17.1 SUSE Linux Enterprise Server 15-SP2-BCL (src): vim-8.0.1568-5.17.1 SUSE Linux Enterprise Server 15-SP1-LTSS (src): vim-8.0.1568-5.17.1 SUSE Linux Enterprise Server 15-SP1-BCL (src): vim-8.0.1568-5.17.1 SUSE Linux Enterprise Server 15-LTSS (src): vim-8.0.1568-5.17.1 SUSE Linux Enterprise Realtime Extension 15-SP2 (src): vim-8.0.1568-5.17.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP4 (src): vim-8.0.1568-5.17.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (src): vim-8.0.1568-5.17.1 SUSE Linux Enterprise Module for Basesystem 15-SP4 (src): vim-8.0.1568-5.17.1 SUSE Linux Enterprise Module for Basesystem 15-SP3 (src): vim-8.0.1568-5.17.1 SUSE Linux Enterprise Micro 5.1 (src): vim-8.0.1568-5.17.1 SUSE Linux Enterprise Micro 5.0 (src): vim-8.0.1568-5.17.1 SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src): vim-8.0.1568-5.17.1 SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src): vim-8.0.1568-5.17.1 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src): vim-8.0.1568-5.17.1 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src): vim-8.0.1568-5.17.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): vim-8.0.1568-5.17.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): vim-8.0.1568-5.17.1 SUSE Enterprise Storage 7 (src): vim-8.0.1568-5.17.1 SUSE Enterprise Storage 6 (src): vim-8.0.1568-5.17.1 SUSE CaaS Platform 4.0 (src): vim-8.0.1568-5.17.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2022:0736-1: An update that fixes 14 vulnerabilities is now available. Category: security (important) Bug References: 1190533,1190570,1191893,1192478,1192481,1193294,1193298,1194216,1194556,1195004,1195066,1195126,1195202,1195356 CVE References: CVE-2021-3778,CVE-2021-3796,CVE-2021-3872,CVE-2021-3927,CVE-2021-3928,CVE-2021-3984,CVE-2021-4019,CVE-2021-4193,CVE-2021-46059,CVE-2022-0318,CVE-2022-0319,CVE-2022-0351,CVE-2022-0361,CVE-2022-0413 JIRA References: Sources used: openSUSE Leap 15.4 (src): vim-8.0.1568-5.17.1 openSUSE Leap 15.3 (src): vim-8.0.1568-5.17.1
SUSE-SU-2022:0736-2: An update that fixes 14 vulnerabilities is now available. Category: security (important) Bug References: 1190533,1190570,1191893,1192478,1192481,1193294,1193298,1194216,1194556,1195004,1195066,1195126,1195202,1195356 CVE References: CVE-2021-3778,CVE-2021-3796,CVE-2021-3872,CVE-2021-3927,CVE-2021-3928,CVE-2021-3984,CVE-2021-4019,CVE-2021-4193,CVE-2021-46059,CVE-2022-0318,CVE-2022-0319,CVE-2022-0351,CVE-2022-0361,CVE-2022-0413 JIRA References: Sources used: SUSE Linux Enterprise Micro 5.2 (src): vim-8.0.1568-5.17.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.