[ubuntu/plucky-security] vim 2:9.1.0967-1ubuntu4.1 (Accepted)
Hlib Korzhynskyy
hlib.korzhynskyy at canonical.com
Mon Sep 15 12:50:54 UTC 2025
vim (2:9.1.0967-1ubuntu4.1) plucky-security; urgency=medium
* SECURITY UPDATE: Path traversal when opening specially crafted tar/zip
archives.
- debian/patches/CVE-2025-53905.patch: Replace "echohl Error" with call,
remove leading slashes from name, replace tar_secure with g:tar_secure in
runtime/autoload/tar.vim.
- debian/patches/CVE-2025-53906.patch: Add need_rename, replace w! with w,
call warning for path traversal attack, and escape leading "../" in
runtime/autoload/zip.vim.
- CVE-2025-53905
- CVE-2025-53906
Date: 2025-09-11 20:29:16.696395+00:00
Changed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
https://launchpad.net/ubuntu/+source/vim/2:9.1.0967-1ubuntu4.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the plucky-changes
mailing list