Description
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3823-1 | less security update |
Debian DSA |
DSA-5679-1 | less security update |
Ubuntu USN |
USN-6756-1 | less vulnerability |
References
History
Wed, 25 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netapp less
|
|
| CPEs | cpe:2.3:a:netapp:less:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Netapp less
|
|
| Metrics |
ssvc
|
Tue, 17 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Debian
Debian debian Linux Greenwoodsoftware Greenwoodsoftware less Netapp Netapp bootstrap Os Netapp hci Compute Node Netapp hci Storage Nodes Netapp solidfire |
|
| CPEs | cpe:2.3:a:greenwoodsoftware:less:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:hci_storage_nodes:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:solidfire:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Debian
Debian debian Linux Greenwoodsoftware Greenwoodsoftware less Netapp Netapp bootstrap Os Netapp hci Compute Node Netapp hci Storage Nodes Netapp solidfire |
Subscriptions
Debian
Subscribe
Debian Linux
Subscribe
Greenwoodsoftware
Subscribe
Less
Subscribe
Netapp
Subscribe
Bootstrap Os
Subscribe
Hci Compute Node
Subscribe
Hci Storage Nodes
Subscribe
Less
Subscribe
Solidfire
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Rhel Aus
Subscribe
Rhel E4s
Subscribe
Rhel Eus
Subscribe
Rhel Tus
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T02:13:39.027Z
Reserved: 2024-04-13T00:00:00.000Z
Link: CVE-2024-32487
Updated: 2024-08-02T02:13:39.027Z
Status : Analyzed
Published: 2024-04-13T15:15:52.683
Modified: 2025-06-17T20:58:12.907
Link: CVE-2024-32487
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Ubuntu USN