CVE Vulnerabilities

CVE-2004-2264

Published: Dec 31, 2004 | Modified: Apr 11, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Format string bug in the open_altfile function in filename.c for GNU less 382, 381, and 358 might allow local users to cause a denial of service or possibly execute arbitrary code via format strings in the LESSOPEN environment variable. NOTE: since less is not setuid or setgid, then this is not a vulnerability unless there are plausible scenarios under which privilege boundaries could be crossed

Affected Software

Name Vendor Start Version End Version
Less Gnu 358 (including) 358 (including)
Less Gnu 381 (including) 381 (including)
Less Gnu 382 (including) 382 (including)

References