1.28.0
cf-buildpacks-eng
released this
03 Aug 10:53
·
176 commits
to main
since this release
Notably, this release addresses:
USN-6270-1 USN-6270-1: Vim vulnerabilities:
- CVE-2022-2182: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- CVE-2022-2208: NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.5163.
- CVE-2022-2210: Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
- CVE-2022-2231: NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.
- CVE-2022-2257: Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
- CVE-2022-2289: Use After Free in GitHub repository vim/vim prior to 9.0.
- CVE-2022-2285: Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.
- CVE-2022-2286: Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
- CVE-2022-2287: Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
- CVE-2022-2208: NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.5163.
- CVE-2022-2182: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- CVE-2022-2264: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
- CVE-2022-2286: Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
- CVE-2022-2287: Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
- CVE-2022-2231: NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.
- CVE-2022-2210: Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
- CVE-2022-2285: Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.
- CVE-2022-2289: Use After Free in GitHub repository vim/vim prior to 9.0.
- CVE-2022-2284: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
- CVE-2022-2257: Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
-ii vim-common 2:8.2.3995-1ubuntu2.9 all Vi IMproved - Common files
-ii vim-tiny 2:8.2.3995-1ubuntu2.9 amd64 Vi IMproved - enhanced vi editor - compact version
+ii vim-common 2:8.2.3995-1ubuntu2.10 all Vi IMproved - Common files
+ii vim-tiny 2:8.2.3995-1ubuntu2.10 amd64 Vi IMproved - enhanced vi editor - compact version
-ii xxd 2:8.2.3995-1ubuntu2.9 amd64 tool to make (or reverse) a hex dump
+ii xxd 2:8.2.3995-1ubuntu2.10 amd64 tool to make (or reverse) a hex dump