close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
https://github.com/gwsw/less/commit/c6ac6de49698be84d264a0c4c0c40bb870b10144 | patch |
https://greenwoodsoftware.com/less/ | release notes |
https://github.com/gwsw/less/compare/v605...v606 | patch |
https://security.netapp.com/advisory/ntap-20240605-0010/ | third party advisory |
https://lists.debian.org/debian-lts-announce/2024/05/msg00018.html | third party advisory mailing list |