CVE-2024-32487
published 2024-04-13CVE-2024-32487: less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically…
PriorityP342high8.6CVSS 3.1
AVLACLPRNUIRSCCHIHAH
EPSS
0.63%
45.9th percentile
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | less | < less 590-2.1~deb12u2 (bookworm) | less 590-2.1~deb12u2 (bookworm) |
| gnu | less | >= 0 < 551-2+deb11u2 | 551-2+deb11u2 |
| gnu | less | >= 0 < 590-2.1~deb12u2 | 590-2.1~deb12u2 |
| gnu | less | >= 0 < 590-2.1 | 590-2.1 |
| gnu | less | >= 0 < 590-2.1 | 590-2.1 |
| greenwoodsoftware | less | <= 653 | — |
| msrc | azl3_less_643-2_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_less_590-4_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
osv8.6HIGH
vendor_debian8.6HIGH
vendor_msrc8.6HIGH
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
less vulnerability
vendor_ubuntu·2024-04-29
CVE-2024-32487 less vulnerability
Title: less vulnerability
Summary: less could be made run programs as your login if it opened a specially
crafted file.
It was discovered that less mishandled newline characters in file names. If
a user or automated system were tricked into opening specially crafted
files, an attacker could possibly use this issue to execute arbitrary
commands on the host.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
less: OS command injection
vendor_redhat·2024-04-13·CVSS 8.6
CVE-2024-32487 [HIGH] CWE-78 less: OS command injection
less: OS command injection
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.
An OS command injection flaw was found in Less. Since quoting is mishandled in filename.c, opening files with attacker-controlled file names can lead to OS command execution. Exploitation requires the LESSOPEN environment variable, which is set by default in many common cases.
Statement: The described vulnerability in less poses an Important security risk due to its potential for arbitrary O
Microsoft
less through 653 allows OS command execution via a newline character in the name of a file because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled fil
vendor_msrc·2024-04-09·CVSS 8.6
CVE-2024-32487 [HIGH] CWE-96 less through 653 allows OS command execution via a newline character in the name of a file because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled fil
less through 653 allows OS command execution via a newline character in the name of a file because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable but this is set by default in many common cases.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this
Debian
CVE-2024-32487: less - less through 653 allows OS command execution via a newline character in the name...
vendor_debian·2024·CVSS 8.6
CVE-2024-32487 [HIGH] CVE-2024-32487: less - less through 653 allows OS command execution via a newline character in the name...
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.
Scope: local
bookworm: resolved (fixed in 590-2.1~deb12u2)
bullseye: resolved (fixed in 551-2+deb11u2)
forky: resolved (fixed in 590-2.1)
sid: resolved (fixed in 590-2.1)
trixie: resolved (fixed in 590-2.1)
GHSA
GHSA-f53j-pgm5-c4r3: less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename
ghsa_unreviewed·2024-04-13
CVE-2024-32487 [HIGH] CWE-96 GHSA-f53j-pgm5-c4r3: less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.
OSV
CVE-2024-32487: less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename
osv·2024-04-13·CVSS 8.6
CVE-2024-32487 [HIGH] CVE-2024-32487: less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2024/04/15/1https://github.com/gwsw/less/commit/007521ac3c95bc76e3d59c6dbfe75d06c8075c33https://lists.debian.org/debian-lts-announce/2024/05/msg00018.htmlhttps://security.netapp.com/advisory/ntap-20240605-0009/https://www.openwall.com/lists/oss-security/2024/04/12/5https://www.openwall.com/lists/oss-security/2024/04/13/2http://www.openwall.com/lists/oss-security/2024/04/15/1https://github.com/gwsw/less/commit/007521ac3c95bc76e3d59c6dbfe75d06c8075c33https://lists.debian.org/debian-lts-announce/2024/05/msg00018.htmlhttps://security.netapp.com/advisory/ntap-20240605-0009/https://www.openwall.com/lists/oss-security/2024/04/12/5https://www.openwall.com/lists/oss-security/2024/04/13/2
2024-04-13
Published