-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 16 Jul 2019 01:05:10 -0400 Source: neovim Binary: neovim neovim-runtime Architecture: all Version: 0.1.7-4+deb9u1 Distribution: stretch-security Urgency: high Maintainer: all Build Daemon (x86-csail-02) Changed-By: James McCoy Description: neovim - heavily refactored vim fork neovim-runtime - heavily refactored vim fork (runtime files) Closes: 930024 Changes: neovim (0.1.7-4+deb9u1) stretch-security; urgency=high . * Backport upstream patches to address CVE-2019-12735 (Closes: #930024) + vim-patch-8.0.0649 and vim-patch-8.0.0650: autocmd open help 2 times + vim-patch:8.1.0066: nasty autocommand causes using freed memory + vim-patch:8.1.0067: syntax highlighting not working when re-entering a buffer + vim-patch:8.1.0177: defining function in sandbox is inconsistent + vim-patch:8.1.0189: function defined in sandbox not tested + vim-patch:8.1.0205: invalid memory access with invalid modeline + vim-patch:8.1.0506: modeline test fails when run by root + vim-patch:8.1.0538: evaluating a modeline might invoke using a shell command + vim-patch:8.1.0539: cannot build without the sandbox + vim-patch:8.1.0540: may evaluate insecure value when appending to option + vim-patch:8.1.0544: setting 'filetype' in a modeline causes an error + vim-patch:8.1.0546: modeline test with keymap fails + vim-patch:8.1.0547: modeline test with keymap still fails + vim-patch:8.1.0613: when executing an insecure function the secure flag is stuck + vim-patch:8.1.1046: the "secure" variable is used inconsistently + vim-patch:8.1.1365: :source should check sandbox + vim-patch:8.1.1366: using expressions in a modeline is unsafe + vim-patch:8.1.1367: can set 'modelineexpr' in modeline + vim-patch:8.1.1368: modeline test fails with python but without pythonhome + vim-patch:8.1.1382: error when editing test file + vim-patch:8.1.1401: misspelled mkspellmem as makespellmem Checksums-Sha1: f9c9abf5365b6683e601666ccba9c83892de4946 2913610 neovim-runtime_0.1.7-4+deb9u1_all.deb a6d79c525b4d64de606b436c556c88dcecf64045 7775 neovim_0.1.7-4+deb9u1_all.buildinfo Checksums-Sha256: 61baa5d16fb0fc06a4290c6e9dd3a6f0cd157e913cd004f8337e4382777a1936 2913610 neovim-runtime_0.1.7-4+deb9u1_all.deb fd254f368456b5fe242b3753e3ced217142feefc79f401697fe00534d876d487 7775 neovim_0.1.7-4+deb9u1_all.buildinfo Files: d89d6458473bc9fa118510ad4a64e5fa 2913610 editors extra neovim-runtime_0.1.7-4+deb9u1_all.deb f727b06da27d906e0ab3fc3c23620c18 7775 editors extra neovim_0.1.7-4+deb9u1_all.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEUT6sJkHnJYUGfmnJQl1fD/W8hvcFAl02XJkACgkQQl1fD/W8 hvfGIA//bn8m8d0ecYljYx8XOTpNzRu0JSH8jW2qtqcM6q2d+gjlJOGC+q/PsZcC m9JnkV1GUGFkT8T4w6OjqaFYEFsS0Az4Bw5So8757tg8LRQQjn3FQ0QF+VqVpvaB 2IbNfyC35Axtia74X2IK8oX9U0z60zINx/cNZ73pUpeaqTdDoG+7antcc+LQwC5J DujC1cSBO2vz7/9BkpVB3i/abXvPR4r+MQSRV2KS2FSKb85ydbelK6i1QjrguoDn NpUX8MYrcZvUP6694MAiWYH7zGFD4kVi3A6g1L8GOFfrrU/a6JzbCqd76ag8j0xu CX8ZrRGEF7ClsPFf/CGxhN5/L1yHT1SRUMJXUFWsH6ZO2dyt23/fpi0RawXgOU0T DiDIfhTQftFfX9p5fa+ljOE8JXkfpPUn1APNU6eX5Ma1fAhgYdNdr2u6tVXJYlhB Z2dB1IoqIJoRQIwYwttVWyagfelYjWk6wbnbi7VbrZcl4nbQ9c+nMMfxTySbC/gL wqSME7glPuJAL1g1vnplH4er2HKG5GylroZxyvrEz8M53C8TCNt+vzTJLBC5fLVN SzT53MPZ4G7degXptqOg91w3RhylNzZ/7bywtYqxdkEOxw2eAb+83SyosCRfzB9e 3PtD8jlXlrd7rOcoqvEE9z6hFip7bXLsLtJiEga4zMBEurXsK00= =Oqam -----END PGP SIGNATURE-----