-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 16 Jun 2019 13:06:40 -0400 Source: vim Binary: vim-common vim-gui-common vim-runtime vim-doc vim-tiny vim vim-gtk vim-gtk3 vim-nox vim-athena vim-gnome xxd Architecture: amd64 Version: 2:8.0.0197-4+deb9u2 Distribution: stretch-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: James McCoy Description: vim - Vi IMproved - enhanced vi editor vim-athena - Vi IMproved - enhanced vi editor - with Athena GUI vim-common - Vi IMproved - Common files vim-doc - Vi IMproved - HTML documentation vim-gnome - Vi IMproved - enhanced vi editor (dummy package) vim-gtk - Vi IMproved - enhanced vi editor - with GTK2 GUI vim-gtk3 - Vi IMproved - enhanced vi editor - with GTK3 GUI vim-gui-common - Vi IMproved - Common GUI files vim-nox - Vi IMproved - enhanced vi editor - with scripting languages suppo vim-runtime - Vi IMproved - Runtime files vim-tiny - Vi IMproved - enhanced vi editor - compact version xxd - tool to make (or reverse) a hex dump Closes: 930020 Changes: vim (2:8.0.0197-4+deb9u2) stretch-security; urgency=high . * Backport patches to address CVE-2019-12735 (Closes: #930020) + 8.0.0649: when opening a help file the filetype is set several times + 8.0.0651: build failure without the auto command feature + 8.1.0066: nasty autocommand causes using freed memory + 8.1.0177: defining function in sandbox is inconsistent + 8.1.0189: function defined in sandbox not tested + 8.1.0205: invalid memory access with invalid modeline + 8.1.0206: duplicate test function name + 8.1.0208: file left behind after running individual test + 8.1.0506: modelinen test fails when run by root + 8.1.0538: evaluating a modeline might invoke using a shell command + 8.1.0539: cannot build without the sandbox + 8.1.0540: may evaluate insecure value when appending to option + 8.1.0544: setting 'filetype' in a modeline causes an error + 8.1.0546: modeline test with keymap fails + 8.1.0547: modeline test with keymap still fails + 8.1.0613: when executing an insecure function the secure flag is stuck + 8.1.1046: the "secure" variable is used inconsistently + 8.1.1365: source command doesn't check for the sandbox + 8.1.1366: using expressions in a modeline is unsafe + 8.1.1367: can set 'modelineexpr' in modeline + 8.1.1368: modeline test fails with python but without pythonhome + 8.1.1382: error when editing test files + 8.1.1401: misspelled mkspellmem and makespellmem * gbp.conf: Set debian-branch to debian/stretch * gbp.conf: Set upstream-tag to v%(version)s Checksums-Sha1: 17e0a01b4799fdadb4bb6f054266d20c7b844414 3802268 vim-athena-dbgsym_8.0.0197-4+deb9u2_amd64.deb 6d6616df6cfb0cfd69406db2fbe1545a1e8f365e 1252068 vim-athena_8.0.0197-4+deb9u2_amd64.deb cc15c214d396f69b740d0f9552d7a821c0f80bb7 2943676 vim-dbgsym_8.0.0197-4+deb9u2_amd64.deb 4e48d17eff585f968c72ce6b15c2574167eff9b0 4146342 vim-gtk-dbgsym_8.0.0197-4+deb9u2_amd64.deb 13b44cd5fd5d836426f835bba81812d8d42111ba 3970508 vim-gtk3-dbgsym_8.0.0197-4+deb9u2_amd64.deb 968effa189e97bce11a0377306bb364db86dcc52 1264224 vim-gtk3_8.0.0197-4+deb9u2_amd64.deb e0aa668909415e132ce0b3816ec493f09bc19d44 1263298 vim-gtk_8.0.0197-4+deb9u2_amd64.deb 5c794197829abf3f6a40603976c955635b9f8551 3256878 vim-nox-dbgsym_8.0.0197-4+deb9u2_amd64.deb aa6383796fc545366aac3e0c042102fb7b45f95b 1144870 vim-nox_8.0.0197-4+deb9u2_amd64.deb 90220ea8441ad0c1e0fcaaab31ea25f09d6a9edb 1140166 vim-tiny-dbgsym_8.0.0197-4+deb9u2_amd64.deb 29b3136552d271f4fcf2316d295134ff56d194fe 445790 vim-tiny_8.0.0197-4+deb9u2_amd64.deb 59bac26cdaa4773ab6eb436802424cfdd8116301 17971 vim_8.0.0197-4+deb9u2_amd64.buildinfo 73058858590075add73262897c8c0cfbb557f436 1034794 vim_8.0.0197-4+deb9u2_amd64.deb 5542c54e323d74119b4a9910a86eb13171d1ec47 11268 xxd-dbgsym_8.0.0197-4+deb9u2_amd64.deb 328b1b8ee12dc4f6904f333d71ba74c0abd98bc3 132026 xxd_8.0.0197-4+deb9u2_amd64.deb Checksums-Sha256: f97569bd418330fa8bc9509b92c09cfab2d3b41f6fb6cfad3b2786ec0d3dca4a 3802268 vim-athena-dbgsym_8.0.0197-4+deb9u2_amd64.deb 22e30644025fcc16da9df3d217ecc844a31cb0f4a8df06c1b3c534de66905eb8 1252068 vim-athena_8.0.0197-4+deb9u2_amd64.deb 94e90640899f95885c2c7fd690848a575272181c4dab9ff76177914144493872 2943676 vim-dbgsym_8.0.0197-4+deb9u2_amd64.deb 0e2194586cbce2ce1ad7f6da47435f636e587ba80d99e2e91ef873463668893b 4146342 vim-gtk-dbgsym_8.0.0197-4+deb9u2_amd64.deb 8c0c26f2fac9627e2cbdc36ee43b41376223dc2fcafd543b9ce9da29e2f0bd90 3970508 vim-gtk3-dbgsym_8.0.0197-4+deb9u2_amd64.deb 485c9a8a93972aede8ad0f246656af41dbe7253cf1c28f0ed57e4d3ee3a4c6ae 1264224 vim-gtk3_8.0.0197-4+deb9u2_amd64.deb 7a48182bd4962cdb3c9f3b3baa435e53263cbd01ba8fe2f912c046912819dad1 1263298 vim-gtk_8.0.0197-4+deb9u2_amd64.deb e273da572e5314c9c0d08cc015ec7f1b9a3e7129f932321f3225f32784080967 3256878 vim-nox-dbgsym_8.0.0197-4+deb9u2_amd64.deb 9238af99711444f0f8f88041751a367dca47c48815667bafd9aa5bc57671ddbb 1144870 vim-nox_8.0.0197-4+deb9u2_amd64.deb ec24a2f55807e9243e4b1c707d7db987a9937d1dd46754d6401e9f3ee9a8e74e 1140166 vim-tiny-dbgsym_8.0.0197-4+deb9u2_amd64.deb 4643940fe09a75bf107de498989421d485beb0dbfb11c2f1ebe1b203d7bc8238 445790 vim-tiny_8.0.0197-4+deb9u2_amd64.deb 5d54a1c6bb7e64929fb16468c883fcf94c17216b5f76c3c4199612b8c1bb4c4b 17971 vim_8.0.0197-4+deb9u2_amd64.buildinfo 634c55b059baccde101ee97e5577e73ce2fa699be8a2ceb08b36615ebc4e0723 1034794 vim_8.0.0197-4+deb9u2_amd64.deb 3d0f9b54c65aa4b37926e3cf5ab472645d4793599590acc6da0cf2577cce8b67 11268 xxd-dbgsym_8.0.0197-4+deb9u2_amd64.deb e2d08c5a9071f26b5f93a113a11e1639c355a55f8e6bed2074d2b90524690e07 132026 xxd_8.0.0197-4+deb9u2_amd64.deb Files: 60323b6a6c1c448f9d819029865f5351 3802268 debug extra vim-athena-dbgsym_8.0.0197-4+deb9u2_amd64.deb 64f6fdb9aa54755645357f96593632c9 1252068 editors extra vim-athena_8.0.0197-4+deb9u2_amd64.deb d0d4d99576a7a0e0932850166c48b281 2943676 debug extra vim-dbgsym_8.0.0197-4+deb9u2_amd64.deb dc5c602cbe43041cf68808a60abb8670 4146342 debug extra vim-gtk-dbgsym_8.0.0197-4+deb9u2_amd64.deb 53535aba89746547a9139245952ac6c4 3970508 debug extra vim-gtk3-dbgsym_8.0.0197-4+deb9u2_amd64.deb 7eb79f93fe3d474eb291a5fce3c4fa8f 1264224 editors extra vim-gtk3_8.0.0197-4+deb9u2_amd64.deb 850eeb45c404e17822041dec0199465f 1263298 editors extra vim-gtk_8.0.0197-4+deb9u2_amd64.deb 0a2edf95fb1a5cf8205d530bf2f09104 3256878 debug extra vim-nox-dbgsym_8.0.0197-4+deb9u2_amd64.deb d08cb18328812bb44867502495de8c3a 1144870 editors extra vim-nox_8.0.0197-4+deb9u2_amd64.deb 1ff2b570a5288f978d14947ec387cebc 1140166 debug extra vim-tiny-dbgsym_8.0.0197-4+deb9u2_amd64.deb 292e3e9efbee28509b5c06d1abb8baa1 445790 editors important vim-tiny_8.0.0197-4+deb9u2_amd64.deb d7d5b06386d8138c1f5495ac78d11d8c 17971 editors optional vim_8.0.0197-4+deb9u2_amd64.buildinfo 8dbb70ee25ea89df6305ede42e001237 1034794 editors optional vim_8.0.0197-4+deb9u2_amd64.deb 3cabb14813c1f16eacb7db60a85c5560 11268 debug extra xxd-dbgsym_8.0.0197-4+deb9u2_amd64.deb b8be8589b7242514acf2e5bde822efb3 132026 editors extra xxd_8.0.0197-4+deb9u2_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEc1Y9tvYCx8z2wuljZWBroU7DAFMFAl0IXC4ACgkQZWBroU7D AFMqehAAqLl7UWInkqA3jDfQ0OQQUopbGCwiNJWsMi4T8p8WXMnAw3NcPJSkYsXt /NbF1N+1tzkox1F+cN90YEFEUmf6FE5O3aJkqArFbCJwbb+NrvYPbxyRdJoiu/Fh y7yNyKQN/+LXJdh2JoLmuNWQqVL6W2mB6SQQRYkbAPdceIPmRXm2hbFLSeelpvT5 Ibq4IuGVyPVR6D73PUKlzatdu2HtKKXma+rGHtHXvczq2Sx87NsutTvTmcVBzcs2 GXUivsCRxsThABRsVFulADOrVV7J6Z97K/I2v18/Iiiatvb0k2rjcNnb5F/2t90v jHfQUJThKfa8kg6dbEXdYqowTSTxjWlUY1TtKJMUaYC5AnQg5OG8L/p2+aC0BlX8 tGQISdUaCfhvWFfNIoiAXjrHS//sGRqawkjU+X4D6cmmYFOXredYQGXQFKidR478 il9wNbmVzSRaKeSP29DjvGHT1sNAvJsQX0DOStVICuLLUhHPmAIB+bAJpjexN4Vy kPXxalffihADwE5d1v1OYRXaWBsDoSqUnppbyciteecO5z/to7ByeKqE1LBpn0H/ nQ7KAkRLr+d+YeqlhoRV89W7mlcdX1p9Oscj9K/45hm8hxeZzYYkIhuX3EQDZELc 9e8/QlqHpJCXNyFqmhcya5ogwVZgUEzyefZhCj5ceyoPS1r3SZc= =Z6+e -----END PGP SIGNATURE-----