Note: This is a public test instance of Red Hat Bugzilla. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback at bugzilla.redhat.com.

Bug 1717503

Summary: Security issue: patch 8.1.1365: source command doesn't check for the sandbox
Product: [Fedora] Fedora Reporter: JayJayJazz <jayjayjazz>
Component: vimAssignee: Karsten Hopp <karsten>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: urgent Docs Contact:
Priority: unspecified    
Version: 29CC: darunesh, gchamoul, karsten, zdohnal
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: All   
URL: https://github.com/vim/vim/releases/tag/v8.1.1365
Whiteboard:
Fixed In Version: vim-8.1.1471-1.fc30 vim-8.1.1471-1.fc29 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-08 00:58:18 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description JayJayJazz 2019-06-05 15:48:16 UTC
Description of problem:
There is a security issue in vim with a version lower than 8.1.1365.

Version-Release number of selected component (if applicable):
8.1.1365

Actual results:
For F29 the available version is vim-8.1.1359-1.fc29 in testing repos.

Expected results:
At least vim 8.1.1365 should be avilable for F29, because it fixes the security issue.

Additional info:
Details about the security issue:
https://github.com/numirias/security/blob/master/doc/2019-06-04_ace-vim-neovim.md

Release of vim:
https://github.com/vim/vim/releases/tag/v8.1.1365

Comment 1 Zdenek Dohnal 2019-06-06 06:26:12 UTC
Hi,

thank you for reporting the issue! There will be Bodhi update in two hours, which will fix it.

Comment 2 Zdenek Dohnal 2019-06-06 06:53:33 UTC
Actually current upstream cannot be built because desktop file error, investigating.

Comment 3 Zdenek Dohnal 2019-06-06 11:19:05 UTC
Issue with desktop files was solved, F29 build will come in half an hour.

Comment 4 Fedora Update System 2019-06-06 11:48:58 UTC
FEDORA-2019-dcd49378b8 has been submitted as an update to Fedora 29. https://bodhi.fedoraproject.org/updates/FEDORA-2019-dcd49378b8

Comment 5 Fedora Update System 2019-06-07 05:08:32 UTC
vim-8.1.1471-1.fc29 has been pushed to the Fedora 29 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2019-dcd49378b8

Comment 6 Zdenek Dohnal 2019-06-07 07:52:46 UTC
*** Bug 1717949 has been marked as a duplicate of this bug. ***

Comment 7 Fedora Update System 2019-06-07 07:54:59 UTC
FEDORA-2019-d79f89346c has been submitted as an update to Fedora 30. https://bodhi.fedoraproject.org/updates/FEDORA-2019-d79f89346c

Comment 8 Fedora Update System 2019-06-08 00:58:18 UTC
vim-8.1.1471-1.fc30 has been pushed to the Fedora 30 stable repository. If problems still persist, please make note of it in this bug report.

Comment 9 Fedora Update System 2019-06-13 01:38:21 UTC
vim-8.1.1471-1.fc29 has been pushed to the Fedora 29 stable repository. If problems still persist, please make note of it in this bug report.