Msrc Cbl2 Less 590-4 On Cbl Mariner 2.0 vulnerabilities
2 known vulnerabilities affecting msrc/cbl2_less_590-4_on_cbl_mariner_2.0.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2024-32487HIGHCVSS 8.62024-04-09
CVE-2024-32487 [HIGH] CWE-96 less through 653 allows OS command execution via a newline character in the name of a file because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled fil
less through 653 allows OS command execution via a newline character in the name of a file because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names such as the files extracted from an untrusted archive. Exploit
msrc
CVE-2022-48624HIGHCVSS 7.82024-02-13
CVE-2022-48624 [HIGH] close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secur
msrc