ELA-1089-1 less security update

arbitrary command execution

2024-05-08
Packageless
Version458-3+deb8u1 (jessie), 481-2.1+deb9u1 (stretch)
Related CVEs CVE-2022-48624 CVE-2024-32487


Several vulnerabilities were discovered in less, a file pager, which may result in the execution of arbitrary commands if a file with a specially crafted file name is processed.



For Debian 8 jessie, these problems have been fixed in version 458-3+deb8u1.

For Debian 9 stretch, these problems have been fixed in version 481-2.1+deb9u1.

We recommend that you upgrade your less packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.