flatcar / Flatcar

Flatcar project repository for issue tracking, project documentation, etc.

Home Page:https://www.flatcar.org/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

update: less

dongsupark opened this issue · comments

Name: less
CVEs: CVE-2024-32487
CVSSs: n/a
Action Needed: update to >= 643-r2

Summary: less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.

refmap.gentoo: https://bugs.gentoo.org/929210