-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 19 Oct 2021 21:56:40 -0400 Source: vim Architecture: source Version: 2:8.1.0875-5+deb10u1 Distribution: buster Urgency: medium Maintainer: Debian Vim Maintainers <team+vim@tracker.debian.org> Changed-By: James McCoy <jamessan@debian.org> Closes: 994076 994497 994498 996593 Changes: vim (2:8.1.0875-5+deb10u1) buster; urgency=medium . * Change gbp.conf and salsa config to use buster * Backport 8.1.0881 and 8.1.0883 to fix CVE-2019-20807 + 8.1.0881: can execute shell commands in rvim through interfaces + 8.1.0883: missing some changes for Ex commands * Backport patches 8.1.0936, 8.2.3402, and 8.2.3403 to fix CVE-2021-3770 (Closes: #994076) + 8.1.0936: may leak memory when using 'vartabstop' + 8.2.3402: invalid memory access when using :retab with large value + 8.2.3403: memory leak for :retab with invalid argument * Backport v8.2.3409 to fix CVE-2021-3778 (Closes: #994498) + 8.2.3409: reading beyond end of line with invalid utf-8 character * Backport v8.2.3428 to fix CVE-2021-3796 (Closes: #994497) + 8.2.3428: using freed memory when replacing * Backport v8.2.3489 to fix CVE-2021-3875 (Closes: #996593) + 8.2.3489: ml_get error after search with range Checksums-Sha1: 2c4f4275e7dc092dc495236e1c1eae8c8e997032 2950 vim_8.1.0875-5+deb10u1.dsc 7cf76114f9de6beaeab6a1b80628bb1a85af1e93 189104 vim_8.1.0875-5+deb10u1.debian.tar.xz Checksums-Sha256: f053973205aba6b1690640c6c636c54d3f62172706795f5d5f50e8b3f783e089 2950 vim_8.1.0875-5+deb10u1.dsc bc0c24a80e13465aacefddaecd242ae093e5552189cebe79548689859392046c 189104 vim_8.1.0875-5+deb10u1.debian.tar.xz Files: a8f5cd84020322bec18109155876c85b 2950 editors optional vim_8.1.0875-5+deb10u1.dsc 5ea2c64cd0663be621b90c2f302ec862 189104 editors optional vim_8.1.0875-5+deb10u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEEkb+/TWlWvV33ty0j3+aRrjMbo9sFAmGrrLVfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDkx QkZCRjRENjk1NkJENURGN0I3MkQyM0RGRTY5MUFFMzMxQkEzREIACgkQ3+aRrjMb o9uSGw/+NFqnHCBnfPasd6SHwZAYkYT1V/dEVh8RdwrARphf7M8fBJkL4xjXBenq 2bInTwBVp6wFEuIxeOJ/fDvbzWXvAaoeiwv1jny/NQdX/kpLdTViepW9Z3cubQn5 fvvPwAhXFjNvllZvF7NUYrWBWeKJQVbO/YKb6DSO71dG9StwyEHoZ47p3zoz9Cts y6Fr14J+5N3i2W+xvWUzVtmk8Fny0Dh7Rn9QVAMJoubumB1OXsrF5IqJFy903KGe N3Qjcq8i873asUTgA9uiV9jIJitt2DsJGr8u8OM9/4wZ2JOEMR3C07C+j7GmzHxE mgFdsg50pks5A25Lcr5qmw2mw1aFZhXvn4U+/Rsc0f2cukKjsKKIKsJ/OOseXyCm F8IHo1+Yx5015Q+6427A5FThrwGhVcx2E3oHbhH8Mm4zcyFqW1FcOEU3HsLHE5Na nq2aQ/q3Fz6pjPgxbsS0c3X0+0rrIpv4IIlestjwggk93zGCQu65EPL090NaEhJ8 nRr1O3uFZYbADf1nQhjdQWgV40g0Lq1M8oWC0jTMLkRENxz99JmTcmVLBewTjgNP 23HECPtRwTDDcj3A1HKQU1BGYfeaZx/no/L5FqqO6TDJ7owaaTxtxG/L5Htyw3xl klTVK4Y91XkCr/af2J82Hj2htSo89Zwsvuqh/ZCxrZwifkmX9XY= =YRyW -----END PGP SIGNATURE-----