First published: Tue Feb 07 2023(Updated: )
In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU less | >=566<609 | |
Fedoraproject Fedora | =37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-46663 is a vulnerability in GNU Less before version 609 where crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal.
CVE-2022-46663 has a severity rating of 7.5 (high).
CVE-2022-46663 can affect you if you use GNU Less before version 609 and receive crafted data, as it may allow ANSI escape sequences to be executed on your terminal.
To fix CVE-2022-46663, update GNU Less to version 609 or later.
You can find more information about CVE-2022-46663 on the following websites: [http://www.greenwoodsoftware.com/less/news.609.html](http://www.greenwoodsoftware.com/less/news.609.html), [http://www.openwall.com/lists/oss-security/2023/02/07/7](http://www.openwall.com/lists/oss-security/2023/02/07/7), [https://github.com/gwsw/less/commit/a78e1351113cef564d790a730d657a321624d79c](https://github.com/gwsw/less/commit/a78e1351113cef564d790a730d657a321624d79c).