less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-04-13T00:00:00

Updated: 2024-08-02T02:13:39.027Z

Reserved: 2024-04-13T00:00:00

Link: CVE-2024-32487

cve-icon Vulnrichment

Updated: 2024-08-02T02:13:39.027Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-13T15:15:52.683

Modified: 2024-11-21T09:15:00.647

Link: CVE-2024-32487

cve-icon Redhat

Severity : Important

Publid Date: 2024-04-13T00:00:00Z

Links: CVE-2024-32487 - Bugzilla