CVE-2022-44542
Summary
| CVE | CVE-2022-44542 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-01 01:15:00 UTC |
| Updated | 2022-12-22 20:37:00 UTC |
| Description | lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object destructor execution via a key/value pair in a hash. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| lesspipe: Arbitrary Code Exeecution (GLSA 202211-02) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Release V2.06 with ShellCheck changes and a security fix · wofr06/lesspipe · GitHub |
MISC |
github.com |
|
| 865631 – <app-text/lesspipe-2.06: Perl storable (pst) files security fix |
MISC |
bugs.gentoo.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710679 Gentoo Linux lesspipe Arbitrary Code Execution (ACE) Vulnerability (GLSA 202211-02)