cbcvebase.
CVE-2022-48624
published 2024-02-19

CVE-2022-48624: close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
1.06%
60.6th percentile
close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianless< less 590-2.1~deb12u2 (bookworm)less 590-2.1~deb12u2 (bookworm)
gnuless>= 0 < 551-2+deb11u2551-2+deb11u2
gnuless>= 0 < 590-2.1~deb12u2590-2.1~deb12u2
gnuless>= 0 < 590-2.1590-2.1
gnuless>= 0 < 590-2.1590-2.1
greenwoodsoftwareless< 606606
msrccbl2_less_590-3_on_cbl_mariner_2.0
msrccbl2_less_590-4_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.