less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.
References
| Link | Resource |
|---|---|
| http://www.openwall.com/lists/oss-security/2024/04/15/1 | Mailing List |
| https://github.com/gwsw/less/commit/007521ac3c95bc76e3d59c6dbfe75d06c8075c33 | Patch |
| https://lists.debian.org/debian-lts-announce/2024/05/msg00018.html | Mailing List |
| https://security.netapp.com/advisory/ntap-20240605-0009/ | Vendor Advisory |
| https://www.openwall.com/lists/oss-security/2024/04/12/5 | Mailing List |
| https://www.openwall.com/lists/oss-security/2024/04/13/2 | Mailing List Patch |
| http://www.openwall.com/lists/oss-security/2024/04/15/1 | Mailing List |
| https://github.com/gwsw/less/commit/007521ac3c95bc76e3d59c6dbfe75d06c8075c33 | Patch |
| https://lists.debian.org/debian-lts-announce/2024/05/msg00018.html | Mailing List |
| https://security.netapp.com/advisory/ntap-20240605-0009/ | Vendor Advisory |
| https://www.openwall.com/lists/oss-security/2024/04/12/5 | Mailing List |
| https://www.openwall.com/lists/oss-security/2024/04/13/2 | Mailing List Patch |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
|
History
No history.
Information
Published : 2024-04-13 15:15
Updated : 2025-06-17 20:58
NVD link : CVE-2024-32487
Mitre link : CVE-2024-32487
CVE.ORG link : CVE-2024-32487
JSON object : View
Products Affected
debian
- debian_linux
netapp
- hci_compute_node
- hci_storage_nodes
- solidfire
- bootstrap_os
greenwoodsoftware
- less
CWE
CWE-96
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
