Package: vim
Version: 1:6.3-078+1
Severity: grave
Tags: security

Hi!

Georgi Guninski found another modeline vuln in vim:

  http://www.guninski.com/where_do_you_want_billg_to_go_today_5.html 

I already asked for a CAN number, I'll forward it when I get one.

You can get the Ubuntu debdiff from

  http://patches.ubuntu.com/patches/vim.code-modelines.diff

for fixing sarge and possibly woody. For unstable, you should probably
just upgrade to the latest upstream version.

Thanks,

Martin

-- 
Martin Pitt        http://www.piware.de
Ubuntu Developer   http://www.ubuntu.com
Debian Developer   http://www.debian.org

Attachment: signature.asc
Description: Digital signature

Reply via email to