First published: Mon Feb 19 2024(Updated: )
close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/less | <=487-0.1<=551-2<=590-2 | |
redhat/less | <606 | 606 |
IBM Security Verify Governance, Identity Manager software component | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager virtual appliance component | <=ISVG 10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-48624 is considered a high-severity vulnerability due to its potential to allow local attackers to execute arbitrary commands.
To remediate CVE-2022-48624, upgrade to less version 606 or later.
CVE-2022-48624 affects less versions prior to 606, specifically versions up to 487-0.1, 551-2, and 590-2.
Users of less prior to version 606 on Debian and versions prior to ISVG 10.0.2 on IBM Security Verify Governance are impacted by CVE-2022-48624.
CVE-2022-48624 is caused by the omission of shell_quote calls for LESSCLOSE in the close_altfile function within less.