CVE-2014-9488
published 2015-04-14CVE-2014-9488: The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed UTF-8 characters, which triggers an…
PriorityP340critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.02%
89.4th percentile
The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed UTF-8 characters, which triggers an out-of-bounds read.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | less | < less 481-1 (bookworm) | less 481-1 (bookworm) |
| gnu | less | <= 471 | — |
| gnu | less | >= 0 < 481-1 | 481-1 |
| gnu | less | >= 0 < 481-1 | 481-1 |
| gnu | less | >= 0 < 481-1 | 481-1 |
| gnu | less | >= 0 < 481-1 | 481-1 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0LOW
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pvw4-m8q5-4fhj: The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed UTF-8 characters, which trigg
ghsa_unreviewed·2022-05-14
CVE-2014-9488 [HIGH] CWE-119 GHSA-pvw4-m8q5-4fhj: The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed UTF-8 characters, which trigg
The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed UTF-8 characters, which triggers an out-of-bounds read.
OSV
CVE-2014-9488: The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed UTF-8 characters, which trigg
osv·2015-04-14·CVSS 10.0
CVE-2014-9488 [CRITICAL] CVE-2014-9488: The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed UTF-8 characters, which trigg
The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed UTF-8 characters, which triggers an out-of-bounds read.
Red Hat
less: out of bounds read access in is_utf8_well_formed()
vendor_redhat·2015-03-10·CVSS 10.0
CVE-2014-9488 [CRITICAL] CWE-120 less: out of bounds read access in is_utf8_well_formed()
less: out of bounds read access in is_utf8_well_formed()
The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed UTF-8 characters, which triggers an out-of-bounds read.
An out of bound read, with a maximum of 5 bytes, was found in the way the is_utf8_well_formed() function parsed UTF-8 characters. If less was to be recompiled with an address sanitizer, a specially crafted input could crash less.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: less (Red Hat Enterprise Linux 5
Debian
CVE-2014-9488: less - The is_utf8_well_formed function in GNU less before 475 allows remote attackers ...
vendor_debian·2014·CVSS 10.0
CVE-2014-9488 [CRITICAL] CVE-2014-9488: less - The is_utf8_well_formed function in GNU less before 475 allows remote attackers ...
The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed UTF-8 characters, which triggers an out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 481-1)
bullseye: resolved (fixed in 481-1)
forky: resolved (fixed in 481-1)
sid: resolved (fixed in 481-1)
trixie: resolved (fixed in 481-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9488 less: out of bounds read access in is_utf8_well_formed()
bugzilla·2015-03-12·CVSS 10.0
CVE-2014-9488 [CRITICAL] CVE-2014-9488 less: out of bounds read access in is_utf8_well_formed()
CVE-2014-9488 less: out of bounds read access in is_utf8_well_formed()
The following flaw was reported in less:
An out of bounds read access in the UTF-8 decoding can be triggered with a malformed file in the tool less. The access happens in the function is_utf8_well_formed (charset.c, line 534) due to a truncated multibyte character in the sample file. It affects the latest upstream less version 470. The bug does not crash less, it can only be made visible by running less with valgrind or compiling it with Address Sanitizer. The security impact is likely minor as it is only an invalid read access.
Additional information:
https://blog.fuzzing-project.org/3-less-out-of-bounds-read-access-TFPA-0022014.html
http://seclists.org/oss-sec/2015/q1/797
Discussion:
Created less tracking bugs f
Bugzilla
CVE-2014-9488 less: out of bounds read access in is_utf8_well_formed() [fedora-all]
bugzilla·2015-03-12·CVSS 10.0
CVE-2014-9488 [CRITICAL] CVE-2014-9488 less: out of bounds read access in is_utf8_well_formed() [fedora-all]
CVE-2014-9488 less: out of bounds read access in is_utf8_well_formed() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
http://advisories.mageia.org/MGASA-2015-0139.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/159449.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00077.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2015:199https://blog.fuzzing-project.org/3-less-out-of-bounds-read-access-TFPA-0022014.htmlhttp://advisories.mageia.org/MGASA-2015-0139.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/159449.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00077.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2015:199https://blog.fuzzing-project.org/3-less-out-of-bounds-read-access-TFPA-0022014.html
2015-04-14
Published