Skip to content

1.28.0

Compare
Choose a tag to compare
@cf-buildpacks-eng cf-buildpacks-eng released this 03 Aug 10:53
· 176 commits to main since this release

Notably, this release addresses:

USN-6270-1 USN-6270-1: Vim vulnerabilities:

  • CVE-2022-2182: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
  • CVE-2022-2208: NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.5163.
  • CVE-2022-2210: Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
  • CVE-2022-2231: NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.
  • CVE-2022-2257: Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
  • CVE-2022-2289: Use After Free in GitHub repository vim/vim prior to 9.0.
  • CVE-2022-2285: Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.
  • CVE-2022-2286: Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
  • CVE-2022-2287: Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
  • CVE-2022-2208: NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.5163.
  • CVE-2022-2182: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
  • CVE-2022-2264: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
  • CVE-2022-2286: Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
  • CVE-2022-2287: Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
  • CVE-2022-2231: NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.
  • CVE-2022-2210: Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
  • CVE-2022-2285: Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.
  • CVE-2022-2289: Use After Free in GitHub repository vim/vim prior to 9.0.
  • CVE-2022-2284: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
  • CVE-2022-2257: Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
-ii  vim-common 2:8.2.3995-1ubuntu2.9  all   Vi IMproved - Common files
-ii  vim-tiny   2:8.2.3995-1ubuntu2.9  amd64 Vi IMproved - enhanced vi editor - compact version
+ii  vim-common 2:8.2.3995-1ubuntu2.10 all   Vi IMproved - Common files
+ii  vim-tiny   2:8.2.3995-1ubuntu2.10 amd64 Vi IMproved - enhanced vi editor - compact version
-ii  xxd        2:8.2.3995-1ubuntu2.9  amd64 tool to make (or reverse) a hex dump
+ii  xxd        2:8.2.3995-1ubuntu2.10 amd64 tool to make (or reverse) a hex dump