Assigner | mitre |
Reserved | 2024-02-19 |
Published | 2024-02-19 |
Updated | 2024-07-05 |
Description
close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
References
https://github.com/gwsw/less/commit/c6ac6de49698be84d264a0c4c0c40bb870b10144
https://greenwoodsoftware.com/less/
https://github.com/gwsw/less/compare/v605...v606
https://security.netapp.com/advisory/ntap-20240605-0010/
https://lists.debian.org/debian-lts-announce/2024/05/msg00018.html ([debian-lts-announce] 20240527 [SECURITY] [DLA 3823-1] less security update)