CVE-2005-0086
published 2005-05-02CVE-2005-0086: Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attackers to cause a denial of service (application crash) or possibly execute…
PriorityP426high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.99%
85.8th percentile
Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file, as demonstrated using the UTF-8 locale.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | less | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2005-01-19·CVSS 7.5
CVE-2005-0086 [HIGH] security flaw
security flaw
Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file, as demonstrated using the UTF-8 locale.
Debian
CVE-2005-0086: less - Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attacker...
vendor_debian·2005·CVSS 7.5
CVE-2005-0086 [HIGH] CVE-2005-0086: less - Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attacker...
Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file, as demonstrated using the UTF-8 locale.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-gv3h-5v7c-44c6: Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attackers to cause a denial of service (application crash) or possibly execute
ghsa_unreviewed·2022-05-01
CVE-2005-0086 [HIGH] GHSA-gv3h-5v7c-44c6: Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attackers to cause a denial of service (application crash) or possibly execute
Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file, as demonstrated using the UTF-8 locale.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-0086 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2005-0086 [HIGH] CVE-2005-0086 security flaw
CVE-2005-0086 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file, as demonstrated using the UTF-8 locale.
Bugzilla
CAN-2005-0086, less segfault
bugzilla·2005-01-27
[MEDIUM] CAN-2005-0086, less segfault
CAN-2005-0086, less segfault
Victor Ashik discovered a heap based buffer overflow in less, caused by a
patch added to the less package in Red Hat Enterprise Linux 3. An attacker
could construct a carefully crafted file that could cause less to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0086
to this issue. Note that this issue only affects the version of less
distributed with Red Hat Enterprise Linux 3.
http://rhn.redhat.com/errata/RHSA-2005-068.html
https://bugzilla.redhat.com/beta/show_bug.cgi?id=145527
------- Additional Comments From [email protected] 2005-02-10 19:09:27 ----
*** Bug 2426 has been marked as a duplicate of this bug. ***
------- Additional Comments
http://www.redhat.com/support/errata/RHSA-2005-068.htmlhttps://bugzilla.fedora.us/show_bug.cgi?id=2404https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=145527https://exchange.xforce.ibmcloud.com/vulnerabilities/19131https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11027http://www.redhat.com/support/errata/RHSA-2005-068.htmlhttps://bugzilla.fedora.us/show_bug.cgi?id=2404https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=145527https://exchange.xforce.ibmcloud.com/vulnerabilities/19131https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11027
2005-05-02
Published