V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2024-32487
ANC
High

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Ex…

CVSS
8.6
High
EPSS
0.01
p45
Published
2024-01-01
Updated
2024-01-01
Description

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.

Tags · CWE
CWE-78
CWE-96
CAPEC-6
CAPEC-15
CAPEC-35
CAPEC-43
CAPEC-73
CAPEC-77
CAPEC-81
CAPEC-85
CAPEC-88
CAPEC-108
Affected products
LessLessLessLessLessLessLessLessLessLessLessLessLessLessLessLessLessLessLess
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Timeline
2024-01-01
Published
2024-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.006 · p45
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-35 · CWE-96
└ via CAPEC-35 · CWE-96
└ via CAPEC-35 · CWE-96
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
Tracked
lessTracked
lessTracked
lessTracked
lessTracked
lessTracked
lessTracked
lessTracked
lessTracked
lessTracked
lessTracked
lessTracked
lessTracked
lessTracked
lessTracked
lessTracked
lessTracked
lessTracked
lessTracked
lessTracked
Showing first 20 of 27
Source databases
ANC
AST
DEB
CVE
RED
UBU
Related vulnerabilities