Alpine: vim: security update to 9.1.1003-r0

medium Tenable Self-Hosted Container Security Plugin ID 408582

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- When switching to other buffers using the :all command and visual mode still being active, this may cause
a heap-buffer overflow, because Vim does not properly end visual mode and therefore may try to access
beyond the end of a line in a buffer. In Patch 9.1.1003 Vim will correctly reset the visual mode before
opening other windows and buffers and therefore fix this bug. In addition it does verify that it won't try
to access a position if the position is greater than the corresponding buffer line. Impact is medium since
the user must have switched on visual mode when executing the :all ex command. The Vim project would like
to thank github user gandalf4a for reporting this issue. The issue has been fixed as of Vim patch
v9.1.1003 (CVE-2025-22134)

See Also

https://security.alpinelinux.org/vuln/CVE-2025-22134

Plugin Details

Severity: Medium

ID: 408582

Version: Revision 1.11

Type: Local

Published: 1/14/2025

Updated: 9/29/2025

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.93

CVSS v2

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 3.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2025-22134

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 1/13/2025

Reference Information

CVE: CVE-2025-22134

IAVA: 2025-A-0020-S