High severity8.6NVD Advisory· Published Apr 13, 2024· Updated Jun 17, 2026
CVE-2024-32487
CVE-2024-32487
Description
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
37- cpe:2.3:a:netapp:hci_storage_nodes:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
- less/lessdescription
- osv-coords30 versionspkg:rpm/almalinux/lesspkg:rpm/opensuse/less&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/less&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/less&distro=openSUSE%20Leap%20Micro%205.3pkg:rpm/opensuse/less&distro=openSUSE%20Leap%20Micro%205.4pkg:rpm/opensuse/less&distro=openSUSE%20Tumbleweedpkg:rpm/suse/less&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/less&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/less&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/less&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/less&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/less&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/less&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/less&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/less&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/less&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/less&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/less&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/less&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/less&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/less&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/less&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/less&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/less&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/less&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/less&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/less&distro=SUSE%20Linux%20Micro%206.0pkg:rpm/suse/less&distro=SUSE%20Linux%20Micro%206.1pkg:rpm/suse/less&distro=SUSE%20Manager%20Proxy%204.3pkg:rpm/suse/less&distro=SUSE%20Manager%20Server%204.3
< 590-4.el9_4+ 29 more
- (no CPE)range: < 590-4.el9_4
- (no CPE)range: < 590-150400.3.9.1
- (no CPE)range: < 643-150600.3.3.1
- (no CPE)range: < 590-150400.3.9.1
- (no CPE)range: < 590-150400.3.9.1
- (no CPE)range: < 668-2.1
- (no CPE)range: < 530-150000.3.9.1
- (no CPE)range: < 530-150000.3.9.1
- (no CPE)range: < 530-150000.3.9.1
- (no CPE)range: < 590-150400.3.9.1
- (no CPE)range: < 590-150400.3.9.1
- (no CPE)range: < 530-150000.3.9.1
- (no CPE)range: < 530-150000.3.9.1
- (no CPE)range: < 590-150400.3.9.1
- (no CPE)range: < 590-150400.3.9.1
- (no CPE)range: < 590-150400.3.9.1
- (no CPE)range: < 590-150400.3.9.1
- (no CPE)range: < 643-150600.3.3.1
- (no CPE)range: < 458-7.15.1
- (no CPE)range: < 530-150000.3.9.1
- (no CPE)range: < 530-150000.3.9.1
- (no CPE)range: < 590-150400.3.9.1
- (no CPE)range: < 458-7.15.1
- (no CPE)range: < 530-150000.3.9.1
- (no CPE)range: < 530-150000.3.9.1
- (no CPE)range: < 590-150400.3.9.1
- (no CPE)range: < 633-3.1
- (no CPE)range: < 668-slfo.1.1_1.1
- (no CPE)range: < 590-150400.3.9.1
- (no CPE)range: < 590-150400.3.9.1
Patches
Vulnerability mechanics
References
6- github.com/gwsw/less/commit/007521ac3c95bc76e3d59c6dbfe75d06c8075c33nvdPatch
- www.openwall.com/lists/oss-security/2024/04/13/2nvdMailing ListPatch
- security.netapp.com/advisory/ntap-20240605-0009/nvdVendor Advisory
- www.openwall.com/lists/oss-security/2024/04/15/1nvdMailing List
- lists.debian.org/debian-lts-announce/2024/05/msg00018.htmlnvdMailing List
- www.openwall.com/lists/oss-security/2024/04/12/5nvdMailing List
News mentions
0No linked articles in our index yet.