Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f53j-pgm5-c4r3

Опубликовано: 13 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.

EPSS

Процентиль: 37%
0.00151
Низкий

8.6 High

CVSS3

Дефекты

CWE-96

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 1 года назад

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.

CVSS3: 8.6
redhat
около 1 года назад

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.

CVSS3: 8.6
nvd
около 1 года назад

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.

CVSS3: 8.6
msrc
около 1 года назад

Описание отсутствует

CVSS3: 8.6
debian
около 1 года назад

less through 653 allows OS command execution via a newline character i ...

EPSS

Процентиль: 37%
0.00151
Низкий

8.6 High

CVSS3

Дефекты

CWE-96