[ubuntu/noble-security] vim 2:9.1.0016-1ubuntu7.9 (Accepted)

Hlib Korzhynskyy hlib.korzhynskyy at canonical.com
Mon Sep 15 12:51:00 UTC 2025


vim (2:9.1.0016-1ubuntu7.9) noble-security; urgency=medium

  * SECURITY UPDATE: Path traversal when opening specially crafted tar/zip
    archives.
    - debian/patches/CVE-2025-53905.patch: remove leading slashes from name,
      replace tar_secure with g:tar_secure in runtime/autoload/tar.vim.
    - debian/patches/CVE-2025-53906.patch: Add need_rename, replace w! with w,
      call warning for path traversal attack, and escape leading "../" in
      runtime/autoload/zip.vim.
    - CVE-2025-53905
    - CVE-2025-53906

Date: 2025-09-11 20:30:16.439203+00:00
Changed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
https://launchpad.net/ubuntu/+source/vim/2:9.1.0016-1ubuntu7.9
-------------- next part --------------
Sorry, changesfile not available.


More information about the noble-changes mailing list