less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.
History

Tue, 17 Jun 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Debian
Debian debian Linux
Greenwoodsoftware
Greenwoodsoftware less
Netapp
Netapp bootstrap Os
Netapp hci Compute Node
Netapp hci Storage Nodes
Netapp solidfire
CPEs cpe:2.3:a:greenwoodsoftware:less:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:hci_storage_nodes:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
Vendors & Products Debian
Debian debian Linux
Greenwoodsoftware
Greenwoodsoftware less
Netapp
Netapp bootstrap Os
Netapp hci Compute Node
Netapp hci Storage Nodes
Netapp solidfire

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-04-13T00:00:00

Updated: 2024-08-02T02:13:39.027Z

Reserved: 2024-04-13T00:00:00

Link: CVE-2024-32487

cve-icon Vulnrichment

Updated: 2024-08-02T02:13:39.027Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-13T15:15:52.683

Modified: 2025-06-17T20:58:12.907

Link: CVE-2024-32487

cve-icon Redhat

Severity : Important

Publid Date: 2024-04-13T00:00:00Z

Links: CVE-2024-32487 - Bugzilla