Input validation error in less - CVE-2022-46663

 

Input validation error in less - CVE-2022-46663

Published: February 11, 2023


Vulnerability identifier: #VU72127
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-46663
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of the ANSI escape sequences in the "less -R" output. A remote attacker can trick the victim to run the command against the specially crafted data and perform a denial of service (DoS) attack.


Affected software

less
Red Hat OpenShift Container Platform
Amazon Linux AMI
Gentoo Linux
Oracle Linux
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Oracle Solaris
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
Fedora
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift Virtualization
ObjectScale
less
less-debuginfo
less-debugsource
less-help
less (Red Hat package)
sys-apps/less

How to mitigate CVE-2022-46663

Install updates from vendor's website.

less - update to 609
Red Hat OpenShift Container Platform - addressed in versions 4.12.23, 4.13.5, 4.13.6
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.1
OpenShift Virtualization - update to 4.13.3
ObjectScale - update to 1.4.0
less - update to 590-2
less-debuginfo - update to 590-2
less-debugsource - update to 590-2
less-help - update to 590-2
less (Red Hat package) - update to 590-2.el9_2
less-debugsource - update to 590-150400.3.3.1
less - update to 590-150400.3.3.1
less-debuginfo - update to 590-150400.3.3.1
sys-apps/less - update to 608-r2
less - update to 608-2
less - update to 633-1.fc37

External References

Related Security Bulletins