← Back

CVE-2024-32487

nvd nist
Published: Apr 13, 2024Modified: Jun 17, 2026

JSON object

Loading...
8.6
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 6.0
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.

Affected (5)

Less
1 product
Debian Linux
3 products
Bootstrap Os
Hci Storage Nodes
Solidfire
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 653
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
Hci Compute Node
All versions
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions

References (12)

Source: cve@mitre.org
Mailing ListPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatch

Timeline

No history available yet.