UbuntuUpdates.org

Package "vim-nox"

Name: vim-nox

Description:

Vi IMproved - enhanced vi editor - with scripting languages support

Latest version: 2:9.1.0967-1ubuntu4.1
Release: plucky (25.04)
Level: security
Repository: universe
Head package: vim
Homepage: https://www.vim.org/

Links


Download "vim-nox"


Other versions of "vim-nox" in Plucky

Repository Area Version
base universe 2:9.1.0967-1ubuntu4
updates universe 2:9.1.0967-1ubuntu4.1

Changelog

Version: 2:9.1.0967-1ubuntu4.1 2025-09-15 16:07:51 UTC

  vim (2:9.1.0967-1ubuntu4.1) plucky-security; urgency=medium

  * SECURITY UPDATE: Path traversal when opening specially crafted tar/zip
    archives.
    - debian/patches/CVE-2025-53905.patch: Replace "echohl Error" with call,
      remove leading slashes from name, replace tar_secure with g:tar_secure in
      runtime/autoload/tar.vim.
    - debian/patches/CVE-2025-53906.patch: Add need_rename, replace w! with w,
      call warning for path traversal attack, and escape leading "../" in
      runtime/autoload/zip.vim.
    - CVE-2025-53905
    - CVE-2025-53906

 -- Hlib Korzhynskyy <email address hidden> Wed, 27 Aug 2025 17:17:04 -0230

CVE-2025-53905 Vim is an open source, command line text editor. Prior to version 9.1.1552, a path traversal issue in Vim’s tar.vim plugin can allow overwriting of a
CVE-2025-53906 Vim is an open source, command line text editor. Prior to version 9.1.1551, a path traversal issue in Vim’s zip.vim plugin can allow overwriting of a



About   -   Send Feedback to @ubuntu_updates