安全公告详情

NS-SA-2026-0107

2026-09-07 18:00:00

简介

important: python-webob/vim security update

严重级别

important

主题

An update for python-webob/vim is now available for NewStart CGSL MAIN 7.02.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

python-webob:
vim:


Security Fix(es):
python-webob: A vulnerability was found in the WebOb package. WebOb normalizes the HTTP Location header using urlparse and urljoin. If the URL starts with //, urlparse treats the following part as the hostname, and replaces the original request's hostname. This issue, combined with user interaction, may become a vulnerability.(CVE-2024-42353)
python-webob: bugfix
vim: A flaw was found in Vim. This vulnerability, a heap-buffer-overflow and a segmentation fault, exists in the swap file recovery logic. A local attacker could exploit this by providing a specially crafted swap file. This could lead to a denial of service (DoS) or potentially information disclosure.(CVE-2026-28421)
vim: A flaw was found in Vim. When processing a specially crafted Emacs-style tags file, a heap-based buffer overflow out-of-bounds read vulnerability allows an attacker to trick Vim into reading up to 7 bytes beyond its allocated memory boundary. This could lead to information disclosure or potentially affect the integrity of the application.(CVE-2026-28418)
vim: A flaw was found in Vim, an open-source command-line text editor. Specifically, an operating system (OS) command injection vulnerability exists in the `netrw` standard plugin. A remote attacker could exploit this by tricking a user into opening a specially crafted URL, such as one using the `scp://` protocol handler. Successful exploitation allows the attacker to execute arbitrary shell commands with the same privileges as the Vim process, leading to potential system compromise.(CVE-2026-28417)
vim: A flaw was found in Vim, an open-source command-line text editor. A local user could exploit a stack-buffer-overflow vulnerability in the `build_stl_str_hl()` function by rendering a statusline with a multi-byte fill character on a very wide terminal. This could lead to an integrity impact, where data might be modified.(CVE-2026-28422)
vim: A flaw was found in Vim. A remote attacker could exploit a heap-based buffer overflow and an out-of-bounds read vulnerability in Vim's terminal emulator. This occurs when processing specially crafted Unicode supplementary plane characters, potentially leading to information disclosure and denial of service.(CVE-2026-28420)
vim: A flaw was found in Vim, an open-source command-line text editor. This vulnerability, a heap-based buffer underflow, occurs when Vim processes a specially crafted Emacs-style tags file. If a malicious file with a delimiter at the start of a line is opened, Vim attempts to read memory outside its designated area. This could lead to the disclosure of sensitive information or cause the application to crash, resulting in a denial of service.(CVE-2026-28419)
vim: A flaw was found in Vim, an open source, command line text editor. This heap buffer overflow vulnerability exists in the tag file resolution logic when processing the 'helpfile' option. A local user could exploit this by providing a specially crafted 'helpfile' option value, leading to a heap buffer overflow. This could result in arbitrary code execution or a denial of service.(CVE-2026-25749)
vim: A flaw was found in Vim. By including a newline character in a pattern passed to Vim's glob() function, an attacker may be able to execute arbitrary shell commands. This command injection vulnerability allows for arbitrary code execution, depending on the user's shell settings.(CVE-2026-33412)
vim: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 7.02.07B5.

影响组件

  • python-webob
  • vim

影响产品

  • CGSL MAIN 7.02

更新包

{"fix":[{"product":"CGSL MAIN 7.02","pkgs":[{"binary":["python3-webob-doc-1.8.7-3.zncgsl7.noarch.rpm","python3-webob-1.8.7-3.zncgsl7.noarch.rpm"],"source":"python-webob-1.8.7-3.zncgsl7.src.rpm"},{"binary":["vim-filesystem-9.0.2092-5.zncgsl7.12.noarch.rpm","vim-doc-9.0.2092-5.zncgsl7.12.noarch.rpm","vim-enhanced-9.0.2092-5.zncgsl7.12.x86_64.rpm","vim-X11-9.0.2092-5.zncgsl7.12.x86_64.rpm","vim-data-9.0.2092-5.zncgsl7.12.noarch.rpm","vim-minimal-9.0.2092-5.zncgsl7.12.x86_64.rpm","vim-common-9.0.2092-5.zncgsl7.12.x86_64.rpm"],"source":"vim-9.0.2092-5.zncgsl7.12.src.rpm"}]}]}

CVE

参考