-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 16 Jun 2019 13:06:40 -0400 Source: vim Binary: vim-common vim-gui-common vim-runtime vim-doc vim-tiny vim vim-gtk vim-gtk3 vim-nox vim-athena vim-gnome xxd Architecture: all Version: 2:8.0.0197-4+deb9u2 Distribution: stretch-security Urgency: high Maintainer: all Build Daemon (x86-grnet-02) Changed-By: James McCoy Description: vim - Vi IMproved - enhanced vi editor vim-athena - Vi IMproved - enhanced vi editor - with Athena GUI vim-common - Vi IMproved - Common files vim-doc - Vi IMproved - HTML documentation vim-gnome - Vi IMproved - enhanced vi editor (dummy package) vim-gtk - Vi IMproved - enhanced vi editor - with GTK2 GUI vim-gtk3 - Vi IMproved - enhanced vi editor - with GTK3 GUI vim-gui-common - Vi IMproved - Common GUI files vim-nox - Vi IMproved - enhanced vi editor - with scripting languages suppo vim-runtime - Vi IMproved - Runtime files vim-tiny - Vi IMproved - enhanced vi editor - compact version xxd - tool to make (or reverse) a hex dump Closes: 930020 Changes: vim (2:8.0.0197-4+deb9u2) stretch-security; urgency=high . * Backport patches to address CVE-2019-12735 (Closes: #930020) + 8.0.0649: when opening a help file the filetype is set several times + 8.0.0651: build failure without the auto command feature + 8.1.0066: nasty autocommand causes using freed memory + 8.1.0177: defining function in sandbox is inconsistent + 8.1.0189: function defined in sandbox not tested + 8.1.0205: invalid memory access with invalid modeline + 8.1.0206: duplicate test function name + 8.1.0208: file left behind after running individual test + 8.1.0506: modelinen test fails when run by root + 8.1.0538: evaluating a modeline might invoke using a shell command + 8.1.0539: cannot build without the sandbox + 8.1.0540: may evaluate insecure value when appending to option + 8.1.0544: setting 'filetype' in a modeline causes an error + 8.1.0546: modeline test with keymap fails + 8.1.0547: modeline test with keymap still fails + 8.1.0613: when executing an insecure function the secure flag is stuck + 8.1.1046: the "secure" variable is used inconsistently + 8.1.1365: source command doesn't check for the sandbox + 8.1.1366: using expressions in a modeline is unsafe + 8.1.1367: can set 'modelineexpr' in modeline + 8.1.1368: modeline test fails with python but without pythonhome + 8.1.1382: error when editing test files + 8.1.1401: misspelled mkspellmem and makespellmem * gbp.conf: Set debian-branch to debian/stretch * gbp.conf: Set upstream-tag to v%(version)s Checksums-Sha1: 0eb92f4aa7aa696938b129e0c92299c9243ccf7a 159138 vim-common_8.0.0197-4+deb9u2_all.deb d51cbfc1bd3b5eee53bc04c0ac193d84ef383c18 1914002 vim-doc_8.0.0197-4+deb9u2_all.deb 30f8b419dce5e454d446831a00d67b6f24c2bce5 100978 vim-gnome_8.0.0197-4+deb9u2_all.deb 3e5d3d3094cb912d40ccb34307f0eacb5aeee0c8 159876 vim-gui-common_8.0.0197-4+deb9u2_all.deb 5112b5a9480b8d5a3d4fb9cef7c6a0c1ba94146d 5407632 vim-runtime_8.0.0197-4+deb9u2_all.deb 1799192f3fc1502de5472c1f04c91c79a9f1e0de 17013 vim_8.0.0197-4+deb9u2_all.buildinfo Checksums-Sha256: 85529893340f8c004f2914056261b087bb5602bc81f34c653d2cbf7f19c03223 159138 vim-common_8.0.0197-4+deb9u2_all.deb a75bfffcada4dd5f2b008b6e2c258f26c2e36ebe8c3b2aa83882673668961fa7 1914002 vim-doc_8.0.0197-4+deb9u2_all.deb 841fd101be40d9c9a7b960f2a690ce03858f959765ac285cb81b18019d247881 100978 vim-gnome_8.0.0197-4+deb9u2_all.deb ab41eac9ed9c7b97bafc1bcea932034f6c14b06f3373caf6a2c24a83d0a4e918 159876 vim-gui-common_8.0.0197-4+deb9u2_all.deb 9738820fe89aa74a04ea77c55bb797df0c9bd62292fe5cae0f40c6c8a9e338b4 5407632 vim-runtime_8.0.0197-4+deb9u2_all.deb 325a7d7d6501d00ee7b1a0abf994e8974729f101aa60be57eed70ee870d0eeb9 17013 vim_8.0.0197-4+deb9u2_all.buildinfo Files: 9a0c1d3f1a38fad7cf87b0b73e5215ec 159138 editors important vim-common_8.0.0197-4+deb9u2_all.deb c3e4545b3cedd740ef78e6f3c11ead0b 1914002 doc optional vim-doc_8.0.0197-4+deb9u2_all.deb 491b0aa0722943eb79b073dcd2570cf5 100978 oldlibs extra vim-gnome_8.0.0197-4+deb9u2_all.deb 7579090300a19a2dbc0b9502b62dfff5 159876 editors optional vim-gui-common_8.0.0197-4+deb9u2_all.deb 98be923684982ba8669c9fa6085891e8 5407632 editors optional vim-runtime_8.0.0197-4+deb9u2_all.deb b844587388908a8d50f25d8d46acc796 17013 editors optional vim_8.0.0197-4+deb9u2_all.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXB1S3LWiQoVR3FKJyjTH8GreOxAFAl0IWlEACgkQyjTH8Gre OxBi5BAAjWkyjVfm0QH001sfthK3KZeKJdigZ+PGYiU/ai2U5ypn/Wap+ROmiJPy vfT/nIy5Kt7u811fadWIugzaGpeUBCZ+TM7NcPV30KWu8NokvRlGaaw+mXcGsG0h jAKMzYX9DHj0d/uWEJ4AJFyumhch5377FALjribtGhO62JFxca9lQNIvRpDvxAR4 sj17qqJiMk9r7DbJFAoqq5W/aX6pt6l1CcUkPRgddm/ffWZ1v3+TG7vBw5n7D45m q6b2QsP21lt++fLnvrkKIMngn4sfkTDtGS0LAX5aNoliNrf4p3xr8sayWSLL9LHX 4aO9OudQjSiOMpa6Ynho2EhScaJyY3bTOPc8tPBLz6xkRL92SWVrb8NjcB7d3xqg Wsb7vzNqoPfCeSPN1e4tBAy+fqFCLjJnS3GBfUrWbv7v8ZjEMo0uzgNuoLh/1uuL /dXjsuQsq0JruWYeThiSbPQ6VCPtdeUh9Gn+Iun8j1WHhCQ8l0sIEzMJZt1kUfOs E+sANqO45ZISaftdNwYO77jpaVI3+60M1eErbZEQ3yg1u3zbROKYwrtkGEf1P+uX Ci6r5Z+HZRcG3U1D1GCixz24kbysplsKqZg70NucsGVXdNDyzGKveYVdn079NsRS p4o3IqbDdoqt/2prkU6mnW03RHX5IXjRdH2ivQjvgCY3G+GwvTo= =id0K -----END PGP SIGNATURE-----