Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f53j-pgm5-c4r3

Опубликовано: 13 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.

EPSS

Процентиль: 47%
0.00628
Низкий

8.6 High

CVSS3

Дефекты

CWE-96

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 2 лет назад

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.

CVSS3: 8.6
redhat
больше 2 лет назад

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.

CVSS3: 8.6
nvd
больше 2 лет назад

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.

CVSS3: 8.6
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 8.6
debian
больше 2 лет назад

less through 653 allows OS command execution via a newline character i ...

EPSS

Процентиль: 47%
0.00628
Низкий

8.6 High

CVSS3

Дефекты

CWE-96