Re: [OE-core] [dunfell][PATCH] vim: fix 2021-3796

2021-10-25 Thread Minjae Kim
Hi Steve! I also updated the patch for dunfell. Thanks, Minjae Kim. -=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#157334): https://lists.openembedded.org/g/openembedded-core/message/157334 Mute This Topic: https://lists.openembedded.org/mt/86506

Re: [OE-core] [dunfell][PATCH] vim: fix 2021-3796

2021-10-24 Thread Steve Sakoman
On Thu, Oct 21, 2021 at 5:42 PM Minjae Kim wrote: > > vim is vulnerable to Use After Free > Problem: Checking first character of url twice. > > reference: > https://github.com/vim/vim/commit/35a9a00afcb20897d462a766793ff45534810dc3 Missing your Signed-off-by: The patch also fails to apply on dun

[OE-core] [dunfell][PATCH] vim: fix 2021-3796

2021-10-21 Thread Minjae Kim
vim is vulnerable to Use After Free Problem: Checking first character of url twice. reference: https://github.com/vim/vim/commit/35a9a00afcb20897d462a766793ff45534810dc3 --- .../vim/files/CVE-2021-3796.patch | 70 +++ meta/recipes-support/vim/vim.inc | 1