Logo
vulnerabilityCVE-2024-32487
Name
CVE-2024-32487
Source
NVD ( link)Debian ( link)
Description
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
less
Patched

Vulnerability Ratings#


8.6
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
661
Not Affected
buildroot
master
704
Not Affected
openwrt
master
692-r1
Not Affected
openwrt
openwrt-25.12
685-r1
Not Affected
yocto
master
704
Not Affected
yocto
scarthgap
643
Exploitable

Resolved with patches#


less (yocto:kirkstone)

#
Title
Author
Resolve
1
Fix bug when viewing a file whose name contains a newline.
Mark Nudelman <markn@greenwoodsoftware.com>
CVE-2024-32487