<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="4811f82775ba2e73f4c7806cd79ad5c0"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="561">
  <id>dbg111-gvim</id>
  <title>vim: Security update to 7.2.108</title>
  <release>openSUSE 11.1</release>
  <issued date="1235584178"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=439148" id="439148" title="bug number 439148" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=470100" id="470100" title="bug number 470100" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=465255" id="465255" title="bug number 465255" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=457098" id="457098" title="bug number 457098" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=436755" id="436755" title="bug number 436755" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=406693" id="406693" title="bug number 406693" type="bugzilla"/>
  </references>
  <description>The VI Improved editor (vim) was updated to version 7.2.108
to fix various security problems and other bugs.

CVE-2008-4677: The netrw plugin sent credentials to all
servers. CVE-2009-0316: The python support used a search
path including the current directory, allowing code
injection when python code was used. CVE-2008-2712:
Arbitrary code execution in vim helper plugins
filetype.vim,  zipplugin, xpm.vim, gzip_vim, and netrw were
fixed. CVE-2008-3074: tarplugin code injection
CVE-2008-3075: zipplugin code injection CVE-2008-3076:
several netrw bugs, code injection CVE-2008-6235: code
injection in the netrw plugin CVE-2008-4677: credential
disclosure by netrw plugin
</description>
  <pkglist>
    <collection>
        <package name="vim-debuginfo" arch="i586" version="7.2" release="7.4.1">
          <filename>vim-debuginfo-7.2-7.4.1.i586.rpm</filename>
        </package>
        <package name="vim-debuginfo" arch="ppc" version="7.2" release="7.4.1">
          <filename>vim-debuginfo-7.2-7.4.1.ppc.rpm</filename>
        </package>
        <package name="vim-debuginfo" arch="x86_64" version="7.2" release="7.4.1">
          <filename>vim-debuginfo-7.2-7.4.1.x86_64.rpm</filename>
        </package>
        <package name="vim-debugsource" arch="i586" version="7.2" release="7.4.1">
          <filename>vim-debugsource-7.2-7.4.1.i586.rpm</filename>
        </package>
        <package name="vim-debugsource" arch="ppc" version="7.2" release="7.4.1">
          <filename>vim-debugsource-7.2-7.4.1.ppc.rpm</filename>
        </package>
        <package name="vim-debugsource" arch="x86_64" version="7.2" release="7.4.1">
          <filename>vim-debugsource-7.2-7.4.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
