Summary: | app-editors/vim|gvim modeline nastiness | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sune Kloppenborg Jeppesen (RETIRED) <jaervosz> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | agriffis, ciaran.mccreesh, corsair, hattya, kugelfang, pvdabeel, sejo, tgall, vim |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | All | ||
Whiteboard: | B1 [glsa] koon / 20041215 | ||
Package list: | Runtime testing required: | --- |
Description
Sune Kloppenborg Jeppesen (RETIRED)
![]() *** Bug 73717 has been marked as a duplicate of this bug. *** Patch 6.3.045 fixes this and a number of similar issues. I'll put together new vim and gvim releases for this and I'll do an updated vim-core snapshot whilst I'm at it. Forwarded to vendor-sec. Please keep low profile in Changelog until they say if they want a coordinated release. app-editors/vim-6.3-r2 and app-editors/gvim-6.3-r2 updated. There's also a new app-editors/vim-core-6.3-r3 which isn't strictly necessary for this bug but it's best to keep everything in sync. Keywords are all ~arch, I'll leave it to you people to decide when to do the whole keywording thing. Calling in last stable markers as this is a restricted bug. Please mark app-editors/vim-6.3-r2: ciaranm@gentoo.org: sparc, mips kloeri@gentoo.org: x86, alpha pvdabeel@gentoo.org: ppc kugelfang@gentoo.org: amd64, s390 hattya@gentoo.org: ia64 agriffis@gentoo.org: arm gmsoft@gentoo.org: hppa tgall@gentoo.org: ppc64 Please mark app-editors/vim-6.3-r2: ciaranm@gentoo.org: x86, sparc, mips pvdabeel@gentoo.org: ppc kloeri@gentoo.org: alpha blubb@gentoo.org: amd64 hattya@gentoo.org: ia64 gmsoft@gentoo.org: hppa dostrow@gentoo.org: ~ppc64 Please mark app-editors/vim-core-6.3-r3: ciaranm@gentoo.org: x86, sparc, mips pvdabeel@gentoo.org: ppc kloeri@gentoo.org: alpha kugelfang@gentoo.org: amd64, s390 hattya@gentoo.org: ia64 agriffis@gentoo.org: arm gmsoft@gentoo.org: hppa tgall@gentoo.org: ppc64 If you're somehow not able to mark please respond back and please propose another dev to mark stable. amd64 done x86, sparc, mips done for gvim and vim-core. sparc, mips done for vim. Alpha done. x86 all done. All done on hppa. Ccing sejo for ppc and corsair for ppc64 Please test and mark vim vim-core and gvim stable (referencing this bug). This is still semi-public and will remain that way until the GLSA is out. app-editors/vim-6.3-r2 and app-editors/vim-core-6.3-r3 is now stable on ppc64. there has never been a stable version of gvim on ppc64; due to bug #69453. currently app-editors/gvim-6.3-r2 is marked ~ppc64. Markus stable on ppc (all 3 packages) Thanks everyone. This will be CAN-2004-1138, release is scheduled for tomorrow 14OO UTC stable on ia64. Default configs are not vulnerable (modelines disabled in vimrc by default), setting "B1". GLSA 200412-10, now public, thx everyone. |