INFSA-2024:3513: less security update

Information about definition

Identificator: INFSA-2024:3513

Type: security

Release date: 2024-08-13 14:08:25 UTC

Information about package

The "less" utility is a text file browser that resembles "more", but allows users to move backwards in the file as well as forwards. Since "less" does not read the entire input file at startup, it also starts more quickly than ordinary text editors.

Vulnerabilities description

  • CVE-2024-32487

    less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 8.6 no information
Critical, important, moderate, low

Updated packages