ALPINE-CVE-2023-48706

Source
https://security.alpinelinux.org/vuln/CVE-2023-48706
Import Source
https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2023-48706.json
JSON Data
https://api.osv.dev/v1/vulns/ALPINE-CVE-2023-48706
Upstream
Published
2023-11-22T22:15:08Z
Modified
2026-08-27T22:18:02Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a :s command for the very first time and using a sub-replace-special atom inside the substitution part, it is possible that the recursive :s call causes free-ing of memory which may later then be accessed by the initial :s command. The user must intentionally execute the payload and the whole process is a bit tricky to do since it seems to work only reliably for the very first :s command. It may also cause a crash of Vim. Version 9.0.2121 contains a fix for this issue.

References

Affected packages

Alpine:v3.19 / vim

Package

Name
vim
Purl
pkg:apk/alpine/vim?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.0.2127-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2023-48706.json"

Alpine:v3.20 / vim

Package

Name
vim
Purl
pkg:apk/alpine/vim?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.0.2127-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2023-48706.json"

Alpine:v3.21 / vim

Package

Name
vim
Purl
pkg:apk/alpine/vim?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.0.2127-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2023-48706.json"

Alpine:v3.22 / vim

Package

Name
vim
Purl
pkg:apk/alpine/vim?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.0.2127-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2023-48706.json"

Alpine:v3.23 / vim

Package

Name
vim
Purl
pkg:apk/alpine/vim?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.0.2127-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2023-48706.json"