Note: This is a public test instance of Red Hat Bugzilla. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback at bugzilla.redhat.com.
Bug 1717503 - Security issue: patch 8.1.1365: source command doesn't check for the sandbox
Summary: Security issue: patch 8.1.1365: source command doesn't check for the sandbox
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: vim
Version: 29
Hardware: All
OS: All
unspecified
urgent
Target Milestone: ---
Assignee: Karsten Hopp
QA Contact: Fedora Extras Quality Assurance
URL: https://github.com/vim/vim/releases/t...
Whiteboard:
: 1717949 (view as bug list)
Depends On:
Blocks: 1717942
TreeView+ depends on / blocked
 
Reported: 2019-06-05 15:48 UTC by JayJayJazz
Modified: 2019-06-13 01:38 UTC (History)
4 users (show)

Fixed In Version: vim-8.1.1471-1.fc30 vim-8.1.1471-1.fc29
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-06-08 00:58:18 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description JayJayJazz 2019-06-05 15:48:16 UTC
Description of problem:
There is a security issue in vim with a version lower than 8.1.1365.

Version-Release number of selected component (if applicable):
8.1.1365

Actual results:
For F29 the available version is vim-8.1.1359-1.fc29 in testing repos.

Expected results:
At least vim 8.1.1365 should be avilable for F29, because it fixes the security issue.

Additional info:
Details about the security issue:
https://github.com/numirias/security/blob/master/doc/2019-06-04_ace-vim-neovim.md

Release of vim:
https://github.com/vim/vim/releases/tag/v8.1.1365

Comment 1 Zdenek Dohnal 2019-06-06 06:26:12 UTC
Hi,

thank you for reporting the issue! There will be Bodhi update in two hours, which will fix it.

Comment 2 Zdenek Dohnal 2019-06-06 06:53:33 UTC
Actually current upstream cannot be built because desktop file error, investigating.

Comment 3 Zdenek Dohnal 2019-06-06 11:19:05 UTC
Issue with desktop files was solved, F29 build will come in half an hour.

Comment 4 Fedora Update System 2019-06-06 11:48:58 UTC
FEDORA-2019-dcd49378b8 has been submitted as an update to Fedora 29. https://bodhi.fedoraproject.org/updates/FEDORA-2019-dcd49378b8

Comment 5 Fedora Update System 2019-06-07 05:08:32 UTC
vim-8.1.1471-1.fc29 has been pushed to the Fedora 29 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2019-dcd49378b8

Comment 6 Zdenek Dohnal 2019-06-07 07:52:46 UTC
*** Bug 1717949 has been marked as a duplicate of this bug. ***

Comment 7 Fedora Update System 2019-06-07 07:54:59 UTC
FEDORA-2019-d79f89346c has been submitted as an update to Fedora 30. https://bodhi.fedoraproject.org/updates/FEDORA-2019-d79f89346c

Comment 8 Fedora Update System 2019-06-08 00:58:18 UTC
vim-8.1.1471-1.fc30 has been pushed to the Fedora 30 stable repository. If problems still persist, please make note of it in this bug report.

Comment 9 Fedora Update System 2019-06-13 01:38:21 UTC
vim-8.1.1471-1.fc29 has been pushed to the Fedora 29 stable repository. If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.