Security Advisory vim security update

Advisory: RHSA-2005:122-04
Type: Security Advisory
Severity: Low
Issued on: 2005-02-18
Last updated on: 2005-02-18
Affected Products: Red Hat Desktop (v. 3)
Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux WS (v. 2.1)
Red Hat Enterprise Linux WS (v. 3)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
OVAL: N/A
CVEs (cve.mitre.org): CVE-2005-0069

Details

Updated vim packages that fix a security vulnerability are now available.

This update has been rated as having low security impact by the Red Hat
Security Response Team.

VIM (Vi IMproved) is an updated and improved version of the vi screen-based
editor.

The Debian Security Audit Project discovered an insecure temporary file
usage in VIM. A local user could overwrite or create files as a different
user who happens to run one of the the vulnerable utilities. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0069 to this issue.

All users of VIM are advised to upgrade to these erratum packages, which
contain a backported patche for this issue.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:

http://www.redhat.com/docs/manuals/enterprise/

Updated packages

Red Hat Desktop (v. 3)

SRPMS:
vim-6.3.046-0.30E.3.src.rpm     d0c6d095fc3fd947b96f48cf80fb75d2
 
IA-32:
vim-X11-6.3.046-0.30E.3.i386.rpm
File outdated by:  RHSA-2008:0617
    5ecea903ba72a0e85b5e035b28b4aef9
vim-common-6.3.046-0.30E.3.i386.rpm
File outdated by:  RHSA-2008:0617
    d814d3d83213dfa0517dff6cc27f453a
vim-enhanced-6.3.046-0.30E.3.i386.rpm
File outdated by:  RHSA-2008:0617
    ec4d0de61e6d0b20bfdbe0a29bb8a41f
vim-minimal-6.3.046-0.30E.3.i386.rpm
File outdated by:  RHSA-2008:0617
    f7890066d7cbc0220355c538043e1d56
 
x86_64:
vim-X11-6.3.046-0.30E.3.x86_64.rpm
File outdated by:  RHSA-2008:0617
    8c9d5111273676a1c6f16eef3b2f0822
vim-common-6.3.046-0.30E.3.x86_64.rpm
File outdated by:  RHSA-2008:0617
    32a2aa7b56236079908bb8decdc4877f
vim-enhanced-6.3.046-0.30E.3.x86_64.rpm
File outdated by:  RHSA-2008:0617
    7e46ae1ba637e5d95c532962853943ca
vim-minimal-6.3.046-0.30E.3.x86_64.rpm
File outdated by:  RHSA-2008:0617
    53726767c2dcb8b26c81445c41cc4abf
 
Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
vim-6.0-7.21.src.rpm     25a0d0da8e8dcd06a732260aed6092de
 
IA-32:
vim-X11-6.0-7.21.i386.rpm
File outdated by:  RHSA-2008:0618
    858074120fd8d3aacfa597234bd2bf9e
vim-common-6.0-7.21.i386.rpm
File outdated by:  RHSA-2008:0618
    2dc635b4493df94730bda4f0ce6c3537
vim-enhanced-6.0-7.21.i386.rpm
File outdated by:  RHSA-2008:0618
    55afb35d89ef238125ec9742ff5bb71c
vim-minimal-6.0-7.21.i386.rpm
File outdated by:  RHSA-2008:0618
    57de71f48376a1aeb896e4d2ee824b87
 
IA-64:
vim-X11-6.0-7.21.ia64.rpm
File outdated by:  RHSA-2008:0618
    00f330fbc80b4e95f575128b13266604
vim-common-6.0-7.21.ia64.rpm
File outdated by:  RHSA-2008:0618
    0f2e04e3039df74739f56e3ebcf64076
vim-enhanced-6.0-7.21.ia64.rpm
File outdated by:  RHSA-2008:0618
    a1eb0b17a2c76bf46ec90442f7e99885
vim-minimal-6.0-7.21.ia64.rpm
File outdated by:  RHSA-2008:0618
    4a0c680069a6eff71523ecfc7effbeae
 
Red Hat Enterprise Linux AS (v. 3)

SRPMS:
vim-6.3.046-0.30E.3.src.rpm     d0c6d095fc3fd947b96f48cf80fb75d2
 
IA-32:
vim-X11-6.3.046-0.30E.3.i386.rpm
File outdated by:  RHSA-2008:0617
    5ecea903ba72a0e85b5e035b28b4aef9
vim-common-6.3.046-0.30E.3.i386.rpm
File outdated by:  RHSA-2008:0617
    d814d3d83213dfa0517dff6cc27f453a
vim-enhanced-6.3.046-0.30E.3.i386.rpm
File outdated by:  RHSA-2008:0617
    ec4d0de61e6d0b20bfdbe0a29bb8a41f
vim-minimal-6.3.046-0.30E.3.i386.rpm
File outdated by:  RHSA-2008:0617
    f7890066d7cbc0220355c538043e1d56
 
IA-64:
vim-X11-6.3.046-0.30E.3.ia64.rpm
File outdated by:  RHSA-2008:0617
    6d5b53a1d2ff995eaa980957f448f23d
vim-common-6.3.046-0.30E.3.ia64.rpm
File outdated by:  RHSA-2008:0617
    ff174d2a96c64ec41312c3a7da5494b4
vim-enhanced-6.3.046-0.30E.3.ia64.rpm
File outdated by:  RHSA-2008:0617
    9461ef263141b100edaf384fa44f1262
vim-minimal-6.3.046-0.30E.3.ia64.rpm
File outdated by:  RHSA-2008:0617
    78dc091a9c3d1e111988eced0b81d697
 
PPC:
vim-X11-6.3.046-0.30E.3.ppc.rpm
File outdated by:  RHSA-2008:0617
    1e7ce04e602be9cc364d55f71f1e700e
vim-common-6.3.046-0.30E.3.ppc.rpm
File outdated by:  RHSA-2008:0617
    e4dd0527a573d86a9a9f39953377459b
vim-enhanced-6.3.046-0.30E.3.ppc.rpm
File outdated by:  RHSA-2008:0617
    cf3f4b6152b2c40683bdb5c7308e35be
vim-minimal-6.3.046-0.30E.3.ppc.rpm
File outdated by:  RHSA-2008:0617
    775f2116d03996ce9ccea101ca7250b0
 
s390:
vim-X11-6.3.046-0.30E.3.s390.rpm
File outdated by:  RHSA-2008:0617
    93c551ed8fcaa5884a46bc4cfa2b5d2a
vim-common-6.3.046-0.30E.3.s390.rpm
File outdated by:  RHSA-2008:0617
    9d17aa93c46223feb88dd957606173a6
vim-enhanced-6.3.046-0.30E.3.s390.rpm
File outdated by:  RHSA-2008:0617
    0426391991938cca456ce7ddd2684227
vim-minimal-6.3.046-0.30E.3.s390.rpm
File outdated by:  RHSA-2008:0617
    4ad9e677f5a154733a84eef2fa76167f
 
s390x:
vim-X11-6.3.046-0.30E.3.s390x.rpm
File outdated by:  RHSA-2008:0617
    5adf3d0ac7c6b060fb3a595852614442
vim-common-6.3.046-0.30E.3.s390x.rpm
File outdated by:  RHSA-2008:0617
    c677152124ad31ac7f7c853f36dd9538
vim-enhanced-6.3.046-0.30E.3.s390x.rpm
File outdated by:  RHSA-2008:0617
    43324fd6361cef7eb591cba2a9344885
vim-minimal-6.3.046-0.30E.3.s390x.rpm
File outdated by:  RHSA-2008:0617
    ecab3cd04492c2ef6cef5b6558cf26fe
 
x86_64:
vim-X11-6.3.046-0.30E.3.x86_64.rpm
File outdated by:  RHSA-2008:0617
    8c9d5111273676a1c6f16eef3b2f0822
vim-common-6.3.046-0.30E.3.x86_64.rpm
File outdated by:  RHSA-2008:0617
    32a2aa7b56236079908bb8decdc4877f
vim-enhanced-6.3.046-0.30E.3.x86_64.rpm
File outdated by:  RHSA-2008:0617
    7e46ae1ba637e5d95c532962853943ca
vim-minimal-6.3.046-0.30E.3.x86_64.rpm
File outdated by:  RHSA-2008:0617
    53726767c2dcb8b26c81445c41cc4abf
 
Red Hat Enterprise Linux ES (v. 2.1)

SRPMS:
vim-6.0-7.21.src.rpm     25a0d0da8e8dcd06a732260aed6092de
 
IA-32:
vim-X11-6.0-7.21.i386.rpm
File outdated by:  RHSA-2008:0618
    858074120fd8d3aacfa597234bd2bf9e
vim-common-6.0-7.21.i386.rpm
File outdated by:  RHSA-2008:0618
    2dc635b4493df94730bda4f0ce6c3537
vim-enhanced-6.0-7.21.i386.rpm
File outdated by:  RHSA-2008:0618
    55afb35d89ef238125ec9742ff5bb71c
vim-minimal-6.0-7.21.i386.rpm
File outdated by:  RHSA-2008:0618
    57de71f48376a1aeb896e4d2ee824b87
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
vim-6.3.046-0.30E.3.src.rpm     d0c6d095fc3fd947b96f48cf80fb75d2
 
IA-32:
vim-X11-6.3.046-0.30E.3.i386.rpm
File outdated by:  RHSA-2008:0617
    5ecea903ba72a0e85b5e035b28b4aef9
vim-common-6.3.046-0.30E.3.i386.rpm
File outdated by:  RHSA-2008:0617
    d814d3d83213dfa0517dff6cc27f453a
vim-enhanced-6.3.046-0.30E.3.i386.rpm
File outdated by:  RHSA-2008:0617
    ec4d0de61e6d0b20bfdbe0a29bb8a41f
vim-minimal-6.3.046-0.30E.3.i386.rpm
File outdated by:  RHSA-2008:0617
    f7890066d7cbc0220355c538043e1d56
 
IA-64:
vim-X11-6.3.046-0.30E.3.ia64.rpm
File outdated by:  RHSA-2008:0617
    6d5b53a1d2ff995eaa980957f448f23d
vim-common-6.3.046-0.30E.3.ia64.rpm
File outdated by:  RHSA-2008:0617
    ff174d2a96c64ec41312c3a7da5494b4
vim-enhanced-6.3.046-0.30E.3.ia64.rpm
File outdated by:  RHSA-2008:0617
    9461ef263141b100edaf384fa44f1262
vim-minimal-6.3.046-0.30E.3.ia64.rpm
File outdated by:  RHSA-2008:0617
    78dc091a9c3d1e111988eced0b81d697
 
x86_64:
vim-X11-6.3.046-0.30E.3.x86_64.rpm
File outdated by:  RHSA-2008:0617
    8c9d5111273676a1c6f16eef3b2f0822
vim-common-6.3.046-0.30E.3.x86_64.rpm
File outdated by:  RHSA-2008:0617
    32a2aa7b56236079908bb8decdc4877f
vim-enhanced-6.3.046-0.30E.3.x86_64.rpm
File outdated by:  RHSA-2008:0617
    7e46ae1ba637e5d95c532962853943ca
vim-minimal-6.3.046-0.30E.3.x86_64.rpm
File outdated by:  RHSA-2008:0617
    53726767c2dcb8b26c81445c41cc4abf
 
Red Hat Enterprise Linux WS (v. 2.1)

SRPMS:
vim-6.0-7.21.src.rpm     25a0d0da8e8dcd06a732260aed6092de
 
IA-32:
vim-X11-6.0-7.21.i386.rpm
File outdated by:  RHSA-2008:0618
    858074120fd8d3aacfa597234bd2bf9e
vim-common-6.0-7.21.i386.rpm
File outdated by:  RHSA-2008:0618
    2dc635b4493df94730bda4f0ce6c3537
vim-enhanced-6.0-7.21.i386.rpm
File outdated by:  RHSA-2008:0618
    55afb35d89ef238125ec9742ff5bb71c
vim-minimal-6.0-7.21.i386.rpm
File outdated by:  RHSA-2008:0618
    57de71f48376a1aeb896e4d2ee824b87
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
vim-6.3.046-0.30E.3.src.rpm     d0c6d095fc3fd947b96f48cf80fb75d2
 
IA-32:
vim-X11-6.3.046-0.30E.3.i386.rpm
File outdated by:  RHSA-2008:0617
    5ecea903ba72a0e85b5e035b28b4aef9
vim-common-6.3.046-0.30E.3.i386.rpm
File outdated by:  RHSA-2008:0617
    d814d3d83213dfa0517dff6cc27f453a
vim-enhanced-6.3.046-0.30E.3.i386.rpm
File outdated by:  RHSA-2008:0617
    ec4d0de61e6d0b20bfdbe0a29bb8a41f
vim-minimal-6.3.046-0.30E.3.i386.rpm
File outdated by:  RHSA-2008:0617
    f7890066d7cbc0220355c538043e1d56
 
IA-64:
vim-X11-6.3.046-0.30E.3.ia64.rpm
File outdated by:  RHSA-2008:0617
    6d5b53a1d2ff995eaa980957f448f23d
vim-common-6.3.046-0.30E.3.ia64.rpm
File outdated by:  RHSA-2008:0617
    ff174d2a96c64ec41312c3a7da5494b4
vim-enhanced-6.3.046-0.30E.3.ia64.rpm
File outdated by:  RHSA-2008:0617
    9461ef263141b100edaf384fa44f1262
vim-minimal-6.3.046-0.30E.3.ia64.rpm
File outdated by:  RHSA-2008:0617
    78dc091a9c3d1e111988eced0b81d697
 
x86_64:
vim-X11-6.3.046-0.30E.3.x86_64.rpm
File outdated by:  RHSA-2008:0617
    8c9d5111273676a1c6f16eef3b2f0822
vim-common-6.3.046-0.30E.3.x86_64.rpm
File outdated by:  RHSA-2008:0617
    32a2aa7b56236079908bb8decdc4877f
vim-enhanced-6.3.046-0.30E.3.x86_64.rpm
File outdated by:  RHSA-2008:0617
    7e46ae1ba637e5d95c532962853943ca
vim-minimal-6.3.046-0.30E.3.x86_64.rpm
File outdated by:  RHSA-2008:0617
    53726767c2dcb8b26c81445c41cc4abf
 
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor

SRPMS:
vim-6.0-7.21.src.rpm     25a0d0da8e8dcd06a732260aed6092de
 
IA-64:
vim-X11-6.0-7.21.ia64.rpm
File outdated by:  RHSA-2008:0618
    00f330fbc80b4e95f575128b13266604
vim-common-6.0-7.21.ia64.rpm
File outdated by:  RHSA-2008:0618
    0f2e04e3039df74739f56e3ebcf64076
vim-enhanced-6.0-7.21.ia64.rpm
File outdated by:  RHSA-2008:0618
    a1eb0b17a2c76bf46ec90442f7e99885
vim-minimal-6.0-7.21.ia64.rpm
File outdated by:  RHSA-2008:0618
    4a0c680069a6eff71523ecfc7effbeae
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

144695 - CAN-2005-0069 vim unsafe temporary file usage.


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/