Vulnerabilities > CVE-2022-48624 - Unspecified vulnerability in Greenwoodsoftware Less
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- https://github.com/gwsw/less/commit/c6ac6de49698be84d264a0c4c0c40bb870b10144
- https://github.com/gwsw/less/commit/c6ac6de49698be84d264a0c4c0c40bb870b10144
- https://github.com/gwsw/less/compare/v605...v606
- https://github.com/gwsw/less/compare/v605...v606
- https://greenwoodsoftware.com/less/
- https://greenwoodsoftware.com/less/
- https://lists.debian.org/debian-lts-announce/2024/05/msg00018.html
- https://lists.debian.org/debian-lts-announce/2024/05/msg00018.html
- https://security.netapp.com/advisory/ntap-20240605-0010/
- https://security.netapp.com/advisory/ntap-20240605-0010/