less through 653 allows OS command execution via a newline...
Vulnerability Description
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-32487
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.openwall.com/lists/oss-security/2024/04/13/2
- https://www.openwall.com/lists/oss-security/2024/04/12/5
- https://github.com/gwsw/less/commit/007521ac3c95bc76e3d59c6dbfe75d06c8075c33
- http://www.openwall.com/lists/oss-security/2024/04/15/1
- https://security.netapp.com/advisory/ntap-20240605-0009/
- https://lists.debian.org/debian-lts-announce/2024/05/msg00018.html
More from n/a
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.