REDHAT-BUG-2274980: High severity ibm r10.0 vulnerability
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.
https://github.com/gwsw/less/commit/007521ac3c95bc76e3d59c6dbfe75d06c8075c33 https://www.openwall.com/lists/oss-security/2024/04/12/5 https://www.openwall.com/lists/oss-security/2024/04/13/2
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2274980?
The severity of REDHAT-BUG-2274980 is considered critical due to the potential for OS command execution.
How do I fix REDHAT-BUG-2274980?
To fix REDHAT-BUG-2274980, update the Less software to a version higher than 653 where the vulnerability is patched.
What systems are affected by REDHAT-BUG-2274980?
REDHAT-BUG-2274980 affects systems running Less version 653 and earlier.
What exploitation methods are associated with REDHAT-BUG-2274980?
Exploitation of REDHAT-BUG-2274980 typically involves using attacker-controlled file names and leveraging mishandled quoting in filename.c.
What filing practices should I adopt to mitigate REDHAT-BUG-2274980?
To mitigate REDHAT-BUG-2274980, avoid extracting untrusted archives and be cautious with filenames that include newline characters.