Errata overview
Errata ID 143
Date 2017-08-23
Source package vim
Fixed in version 2:7.4.488-7+deb8u3
Description
This update addresses the following issues:
* Fix an integer overflow at an unserialize_uep memory allocation site if it
  does not properly validate values for tree length when reading a corrupted
  undo file, which may lead to resultant buffer overflows (CVE-2017-6350)
* Fix an integer overflow at a u_read_undo memory allocation site if it does
  not properly validate values for tree length when reading a corrupted undo
  file, which may lead to resultant buffer overflows (CVE-2017-6349)
Additional notes
CVE ID CVE-2017-6350
CVE-2017-6349
UCS Bug number #45178