Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-48624

Опубликовано: 19 фев. 2024
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.

A flaw was found in less. The close_altfile() function in filename.c omits shell_quote calls for LESSCLOSE, a command line to invoke the optional input postprocessor. This issue could lead to an OS command injection vulnerability and arbitrary command execution on the host operating system.

Отчет

To exploit this issue, an attacker needs the ability to influence the LESSCLOSE environment variable. This requirement makes this CVE a Moderate impact CVE.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6lessOut of support scope
Red Hat Enterprise Linux 7lessOut of support scope
Red Hat Enterprise Linux 8lessFixedRHSA-2024:161002.04.2024
Red Hat Enterprise Linux 8lessFixedRHSA-2024:425602.07.2024
Red Hat Enterprise Linux 8.6 Extended Update SupportlessFixedRHSA-2024:198923.04.2024
Red Hat Enterprise Linux 8.8 Extended Update SupportlessFixedRHSA-2024:187518.04.2024
Red Hat Enterprise Linux 9lessFixedRHSA-2024:169208.04.2024
RHOL-5.6-RHEL-8openshift-logging/cluster-logging-operator-bundleFixedRHSA-2024:209201.05.2024
RHOL-5.6-RHEL-8openshift-logging/cluster-logging-rhel8-operatorFixedRHSA-2024:209201.05.2024
RHOL-5.6-RHEL-8openshift-logging/elasticsearch6-rhel8FixedRHSA-2024:209201.05.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=2265081less: missing quoting of shell metacharacters in LESSCLOSE handling

EPSS

Процентиль: 58%
0.00366
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 1 года назад

close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.

CVSS3: 7.8
nvd
больше 1 года назад

close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.

CVSS3: 7.8
msrc
4 месяца назад

Описание отсутствует

CVSS3: 7.8
debian
больше 1 года назад

close_altfile in filename.c in less before 606 omits shell_quote calls ...

suse-cvrf
около 1 года назад

Security update for less

EPSS

Процентиль: 58%
0.00366
Низкий

7 High

CVSS3