VDB
ALPINE-CVE-2023-48231
ALPINE-CVE-2023-48231
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Vim is an open source command line text editor. When closing a window, vim may try to access already freed window structure. Exploitation beyond crashing the application has not been shown to be viable. This issue has been addressed in commit `25aabc2b` which has been included in release version 9.0.2106. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Risk Scores
CVSS v3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alpine:v3.23 | vim | 7.2.284-r0, 9.0.2073-r0, 9.0.1994-r0 |
| Alpine:v3.20 | vim | 9.0.1440-r0, 0, 7.2.394-r1 |
| Alpine:v3.19 | vim | 9.0.2073-r0, 7.2.394-r0, 7.2.411-r0 |
| Alpine:v3.22 | vim | 8.2.1843-r0, 9.0.2073-r0, 9.0.1994-r0 |
| Alpine:v3.21 | vim | 9.0.2073-r0, 7.3.659-r0, 7.2.284-r0 |
Timeline
- Nov 16, 2023 CVE Published
- Dec 3, 2025 CVE Updated
- Apr 30, 2026 Distribution Patch