PT-2024-4011 · Less+10 · Less+10

Tmarkettos

·

Published

2024-02-18

·

Updated

2026-03-05

·

CVE-2022-48624

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: less versions prior to 606
Description: The issue is related to the close altfile function in filename.c, which omits shell quote calls for LESSCLOSE. This can allow an attacker to execute arbitrary commands.
Recommendations: For versions prior to 606, update to version 606 or later to resolve the issue. As a temporary workaround, consider restricting the use of the LESSCLOSE variable to minimize the risk of exploitation.

Fix

Command Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

ALSA-2024:1610
ALSA-2024:1692
ALSA-2024:4256
AZL-34458
BDU:2024-04438
CESA-2024_1610
CESA-2024_4256
CVE-2022-48624
DLA-3823-1
DSA-5679-1
INFSA-2024_4256
OESA-2024-1219
OPENSUSE-SU-2024_1192-1
RHSA-2024:1610
RHSA-2024:1692
RHSA-2024:1875
RHSA-2024:1989
RHSA-2024:4256
RHSA-2024_1610
RHSA-2024_1692
RHSA-2024_4256
RLSA-2024:1610
RLSA-2024:1692
SUSE-SU-2024:1189-1
SUSE-SU-2024:1190-1
SUSE-SU-2024:1192-1
SUSE-SU-2024_1189-1
SUSE-SU-2024_1190-1
SUSE-SU-2024_1192-1
USN-6664-1
USN-8079-1

Affected Products

Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Zvirt Node
Less