CVE-2022-48624
published 2024-02-19CVE-2022-48624: close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
1.06%
60.6th percentile
close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | less | < less 590-2.1~deb12u2 (bookworm) | less 590-2.1~deb12u2 (bookworm) |
| gnu | less | >= 0 < 551-2+deb11u2 | 551-2+deb11u2 |
| gnu | less | >= 0 < 590-2.1~deb12u2 | 590-2.1~deb12u2 |
| gnu | less | >= 0 < 590-2.1 | 590-2.1 |
| gnu | less | >= 0 < 590-2.1 | 590-2.1 |
| greenwoodsoftware | less | < 606 | 606 |
| msrc | cbl2_less_590-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_less_590-4_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-48624: close_altfile in filename
osv·2024-02-19·CVSS 7.8
CVE-2022-48624 [HIGH] CVE-2022-48624: close_altfile in filename
close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
GHSA
GHSA-p647-4jrw-p827: close_altfile in filename
ghsa_unreviewed·2024-02-19
CVE-2022-48624 [HIGH] CWE-78 GHSA-p647-4jrw-p827: close_altfile in filename
close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
Ubuntu
less vulnerability
vendor_ubuntu·2026-03-05
CVE-2022-48624 less vulnerability
Title: less vulnerability
Summary: less could be made to crash or run arbitrary commands if it received
crafted input.
It was discovered that less incorrectly handled certain file names. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary commands.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
less vulnerability
vendor_ubuntu·2024-02-27
CVE-2022-48624 less vulnerability
Title: less vulnerability
Summary: less could be made to crash or run arbitrary commands if it receive
a crafted input.
It was discovered that less incorrectly handled certain file names.
An attacker could possibly use this issue to cause a crash or execute
arbitrary commands.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
less: missing quoting of shell metacharacters in LESSCLOSE handling
vendor_redhat·2024-02-19·CVSS 7.8
CVE-2022-48624 [HIGH] CWE-77 less: missing quoting of shell metacharacters in LESSCLOSE handling
less: missing quoting of shell metacharacters in LESSCLOSE handling
close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
A flaw was found in less. The close_altfile() function in filename.c omits shell_quote calls for LESSCLOSE, a command line to invoke the optional input postprocessor. This issue could lead to an OS command injection vulnerability and arbitrary command execution on the host operating system.
Statement: To exploit this issue, an attacker needs the ability to influence the LESSCLOSE environment variable. This requirement makes this CVE a Moderate impact CVE.
Package: less (Red Hat Enterprise Linux 6) - Out of support scope
Package: less (Red Hat Enterprise Linux 7) - Out of support scope
Microsoft
close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
vendor_msrc·2024-02-13·CVSS 7.8
CVE-2022-48624 [HIGH] close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Remediation: CBL-Mariner Rele
Debian
CVE-2022-48624: less - close_altfile in filename.c in less before 606 omits shell_quote calls for LESSC...
vendor_debian·2022·CVSS 7.8
CVE-2022-48624 [HIGH] CVE-2022-48624: less - close_altfile in filename.c in less before 606 omits shell_quote calls for LESSC...
close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
Scope: local
bookworm: resolved (fixed in 590-2.1~deb12u2)
bullseye: resolved (fixed in 551-2+deb11u2)
forky: resolved (fixed in 590-2.1)
sid: resolved (fixed in 590-2.1)
trixie: resolved (fixed in 590-2.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/gwsw/less/commit/c6ac6de49698be84d264a0c4c0c40bb870b10144https://github.com/gwsw/less/compare/v605...v606https://greenwoodsoftware.com/less/https://lists.debian.org/debian-lts-announce/2024/05/msg00018.htmlhttps://security.netapp.com/advisory/ntap-20240605-0010/https://github.com/gwsw/less/commit/c6ac6de49698be84d264a0c4c0c40bb870b10144https://github.com/gwsw/less/compare/v605...v606https://greenwoodsoftware.com/less/https://lists.debian.org/debian-lts-announce/2024/05/msg00018.htmlhttps://security.netapp.com/advisory/ntap-20240605-0010/
2024-02-19
Published