Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-32487

Опубликовано: 13 апр. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.6

Описание

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.

РелизСтатусПримечание
devel

released

590-2ubuntu2.1
esm-infra-legacy/trusty

not-affected

458-2ubuntu0.1~esm1
esm-infra/bionic

released

487-0.1ubuntu0.1~esm2
esm-infra/focal

not-affected

551-1ubuntu0.3
esm-infra/xenial

released

481-2.1ubuntu0.2+esm2
focal

released

551-1ubuntu0.3
jammy

released

590-1ubuntu0.22.04.3
mantic

released

590-2ubuntu0.23.10.2
noble

released

590-2ubuntu2.1
trusty/esm

released

458-2ubuntu0.1~esm1

Показывать по

EPSS

Процентиль: 37%
0.00151
Низкий

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
redhat
около 1 года назад

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.

CVSS3: 8.6
nvd
около 1 года назад

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.

CVSS3: 8.6
msrc
около 1 года назад

Описание отсутствует

CVSS3: 8.6
debian
около 1 года назад

less through 653 allows OS command execution via a newline character i ...

suse-cvrf
около 1 года назад

Security update for less

EPSS

Процентиль: 37%
0.00151
Низкий

8.6 High

CVSS3

Уязвимость CVE-2024-32487