yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2022-46663
Component Overview
Vulnerability Overview
Name
CVE-2022-46663
Source
NVD (
link
)
Debian (
link
)
Description
In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal.
CWEs
Published Date
Feb 7, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://www.greenwoodsoftware.com/less/news.609.html
Broken Link
http://www.openwall.com/lists/oss-security/2023/02/07/7
Mailing List
https://github.com/gwsw/less/commit/a78e1351113cef564d790a730d657a321624d79c
Patch
https://security.gentoo.org/glsa/202310-11
Third Party Advisory
https://www.openwall.com/lists/oss-security/2023/02/07/7
Mailing List
http://www.greenwoodsoftware.com/less/news.609.html
Broken Link
http://www.openwall.com/lists/oss-security/2023/02/07/7
Mailing List
https://github.com/gwsw/less/commit/a78e1351113cef564d790a730d657a321624d79c
Patch
https://security.gentoo.org/glsa/202310-11
Third Party Advisory
https://www.openwall.com/lists/oss-security/2023/02/07/7
Mailing List
Analysis
#
Affected Component
Analysis
less
Patched
Vulnerability Ratings
#
7.5
CVSSv31
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
less
buildroot
2025.02.x
661
Not Affected
less
buildroot
master
704
Not Affected
less
openwrt
master
692-r1
Not Affected
less
openwrt
openwrt-25.12
685-r1
Not Affected
less
yocto
master
704
Not Affected
less
yocto
scarthgap
643
Not Affected
Resolved with patches
#
less (yocto:kirkstone)
#
Title
Author
Resolve
1
End OSC8 hyperlink on invalid embedded escape sequence.
Mark Nudelman <markn@greenwoodsoftware.com>
CVE-2022-46663