CVE-2022-46663
Summary
| CVE | CVE-2022-46663 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-07 21:15:00 UTC |
| Updated | 2023-11-07 03:55:00 UTC |
| Description | In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 37 | All | All | All |
| Application | Gnu | Less | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| less: Denial of service (GLSA 202310-11) — Gentoo security | GENTOO | security.gentoo.org | |
| End OSC8 hyperlink on invalid embedded escape sequence. · gwsw/less@a78e135 · GitHub | MISC | github.com | |
| [SECURITY] Fedora 37 Update: less-633-1.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| oss-security - CVE-2022-46663: less -R filtering bypass | MISC | www.openwall.com | |
| Greenwood Software | MISC | www.greenwoodsoftware.com | |
| oss-security - CVE-2022-46663: less -R filtering bypass | MLIST | www.openwall.com | |
| [SECURITY] Fedora 37 Update: less-633-1.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160751 Oracle Enterprise Linux Security Update for less (ELSA-2023-3725)
- 183216 Debian Security Update for less (CVE-2022-46663)
- 199168 Ubuntu Security Notification for less Vulnerability (USN-5848-1)
- 241739 Red Hat Update for less (RHSA-2023:3725)
- 284022 Fedora Security Update for less (FEDORA-2023-71442d7613)
- 296099 Oracle Solaris 11.4 Support Repository Update (SRU) 57.144.3 Missing (CPUAPR2023)
- 355219 Amazon Linux Security Advisory for less : ALAS2023-2023-123
- 673135 EulerOS Security Update for less (EulerOS-SA-2023-2297)
- 673168 EulerOS Security Update for less (EulerOS-SA-2023-2273)
- 710770 Gentoo Linux less Denial of Service (DoS) Vulnerability (GLSA 202310-11)
- 753673 SUSE Enterprise Linux Security Update for less (SUSE-SU-2023:0348-1)
- 905465 Common Base Linux Mariner (CBL-Mariner) Security Update for less (13350)
- 906523 Common Base Linux Mariner (CBL-Mariner) Security Update for less (13350-1)
- 906649 Common Base Linux Mariner (CBL-Mariner) Security Update for less (13350-3)
- 941155 AlmaLinux Security Update for less (ALSA-2023:3725)