CVE-2022-46663
published 2023-02-07CVE-2022-46663: In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal.
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.41%
69.5th percentile
In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | less | < less 590-1.2 (bookworm) | less 590-1.2 (bookworm) |
| fedoraproject | fedora | — | — |
| gnu | less | >= 0 < 590-1.2 | 590-1.2 |
| gnu | less | >= 0 < 590-1.2 | 590-1.2 |
| gnu | less | >= 0 < 590-1.2 | 590-1.2 |
| gnu | less | >= 566 < 609 | 609 |
| msrc | less-590-2.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm | — | — |
| msrc | less-590-2.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64 | — | — |
| msrc | less-debuginfo-590-2.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm | — | — |
| msrc | less-debuginfo-590-2.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
In GNU Less before 609 crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal.
vendor_msrc·2023-02-14·CVSS 7.5
CVE-2022-46663 [HIGH] In GNU Less before 609 crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal.
In GNU Less before 609 crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Ye
Ubuntu
less vulnerability
vendor_ubuntu·2023-02-09
CVE-2022-46663 less vulnerability
Title: less vulnerability
Summary: Use of less could result in a denial of service
David Leadbeater discovered that less was not properly handling escape
sequences when displaying raw control characters. A maliciously formed
OSC 8 hyperlink could possibly be used by an attacker to cause a denial of
service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
less: crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal
vendor_redhat·2023-02-07·CVSS 7.5
CVE-2022-46663 [HIGH] less: crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal
less: crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal
In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal.
A vulnerability was found in less. This flaw allows crafted data to result in "less -R" not filtering ANSI escape sequences sent to the terminal.
Package: servicemesh-grafana (OpenShift Service Mesh 2.1) - Not affected
Package: less (Red Hat Enterprise Linux 6) - Not affected
Package: less (Red Hat Enterprise Linux 7) - Not affected
Package: less (Red Hat Enterprise Linux 8) - Not affected
Package: less (Red Hat Fuse 7) - Not affected
Package: less (Red Hat JBoss Data Grid 7) - Not affected
Package: less (Red Hat JBoss Enterprise Application Platform 7) - Not affect
Debian
CVE-2022-46663: less - In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI ...
vendor_debian·2022·CVSS 7.5
CVE-2022-46663 [HIGH] CVE-2022-46663: less - In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI ...
In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal.
Scope: local
bookworm: resolved (fixed in 590-1.2)
bullseye: resolved
forky: resolved (fixed in 590-1.2)
sid: resolved (fixed in 590-1.2)
trixie: resolved (fixed in 590-1.2)
GHSA
GHSA-5xw7-xf7p-gm82: In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal
ghsa_unreviewed·2023-02-07
CVE-2022-46663 [HIGH] GHSA-5xw7-xf7p-gm82: In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal
In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal.
OSV
CVE-2022-46663: In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal
osv·2023-02-07·CVSS 7.5
CVE-2022-46663 [HIGH] CVE-2022-46663: In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal
In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.greenwoodsoftware.com/less/news.609.htmlhttp://www.openwall.com/lists/oss-security/2023/02/07/7https://github.com/gwsw/less/commit/a78e1351113cef564d790a730d657a321624d79chttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LR7AUWB34JD4PCW3HHASBEDGGHFWPAQP/https://security.gentoo.org/glsa/202310-11https://www.openwall.com/lists/oss-security/2023/02/07/7http://www.greenwoodsoftware.com/less/news.609.htmlhttp://www.openwall.com/lists/oss-security/2023/02/07/7https://github.com/gwsw/less/commit/a78e1351113cef564d790a730d657a321624d79chttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LR7AUWB34JD4PCW3HHASBEDGGHFWPAQP/https://security.gentoo.org/glsa/202310-11https://www.openwall.com/lists/oss-security/2023/02/07/7
2023-02-07
Published