yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2022-48624
Component Overview
Vulnerability Overview
Name
CVE-2022-48624
Source
NVD (
link
)
Debian (
link
)
Description
close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
CWEs
CWE-78
Published Date
Feb 19, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/gwsw/less/commit/c6ac6de49698be84d264a0c4c0c40bb870b10144
Patch
https://github.com/gwsw/less/compare/v605...v606
Patch
https://greenwoodsoftware.com/less/
Release Notes
https://lists.debian.org/debian-lts-announce/2024/05/msg00018.html
Mailing List
https://security.netapp.com/advisory/ntap-20240605-0010/
Third Party Advisory
https://github.com/gwsw/less/commit/c6ac6de49698be84d264a0c4c0c40bb870b10144
Patch
https://github.com/gwsw/less/compare/v605...v606
Patch
https://greenwoodsoftware.com/less/
Release Notes
https://lists.debian.org/debian-lts-announce/2024/05/msg00018.html
Mailing List
https://security.netapp.com/advisory/ntap-20240605-0010/
Third Party Advisory
Analysis
#
Affected Component
Analysis
less
Patched
Vulnerability Ratings
#
7.8
CVSSv31
7.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
less
buildroot
2025.02.x
661
Not Affected
less
buildroot
master
704
Not Affected
less
openwrt
master
692-r1
Not Affected
less
openwrt
openwrt-25.12
685-r1
Not Affected
less
yocto
master
704
Not Affected
less
yocto
scarthgap
643
Not Affected
Resolved with patches
#
less (yocto:kirkstone)
#
Title
Author
Resolve
1
Shell-quote filenames when invoking LESSCLOSE.
Mark Nudelman <markn@greenwoodsoftware.com>
CVE-2022-48624