[ALAS2-2024-2547] Amazon Linux 2 2017.12 - ALAS2-2024-2547: important priority package update for less
Severity
Important
Affected Packages
6
CVEs
1
Package updates are available for Amazon Linux 2 that fix the following vulnerabilities:
CVE-2024-32487:
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.
Package | Affected Version |
---|---|
pkg:rpm/amazonlinux/less?arch=x86_64&distro=amazonlinux-2 | < 458-9.amzn2.0.4 |
pkg:rpm/amazonlinux/less?arch=i686&distro=amazonlinux-2 | < 458-9.amzn2.0.4 |
pkg:rpm/amazonlinux/less?arch=aarch64&distro=amazonlinux-2 | < 458-9.amzn2.0.4 |
pkg:rpm/amazonlinux/less-debuginfo?arch=x86_64&distro=amazonlinux-2 | < 458-9.amzn2.0.4 |
pkg:rpm/amazonlinux/less-debuginfo?arch=i686&distro=amazonlinux-2 | < 458-9.amzn2.0.4 |
pkg:rpm/amazonlinux/less-debuginfo?arch=aarch64&distro=amazonlinux-2 | < 458-9.amzn2.0.4 |
- ID
- ALAS2-2024-2547
- Severity
- important
- URL
- https://alas.aws.amazon.com/AL2/ALAS-2024-2547.html
- Published
-
2024-05-23T22:04:00
(3 months ago) - Modified
-
2024-05-23T22:04:00
(3 months ago) - Rights
- Amazon Linux Security Team
- Other Advisories
Source | # ID | Name | URL |
---|---|---|---|
CVE | CVE-2024-32487 | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-32487 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/amazonlinux/less?arch=x86_64&distro=amazonlinux-2 | amazonlinux | less | < 458-9.amzn2.0.4 | amazonlinux-2 | x86_64 | |
Affected | pkg:rpm/amazonlinux/less?arch=i686&distro=amazonlinux-2 | amazonlinux | less | < 458-9.amzn2.0.4 | amazonlinux-2 | i686 | |
Affected | pkg:rpm/amazonlinux/less?arch=aarch64&distro=amazonlinux-2 | amazonlinux | less | < 458-9.amzn2.0.4 | amazonlinux-2 | aarch64 | |
Affected | pkg:rpm/amazonlinux/less-debuginfo?arch=x86_64&distro=amazonlinux-2 | amazonlinux | less-debuginfo | < 458-9.amzn2.0.4 | amazonlinux-2 | x86_64 | |
Affected | pkg:rpm/amazonlinux/less-debuginfo?arch=i686&distro=amazonlinux-2 | amazonlinux | less-debuginfo | < 458-9.amzn2.0.4 | amazonlinux-2 | i686 | |
Affected | pkg:rpm/amazonlinux/less-debuginfo?arch=aarch64&distro=amazonlinux-2 | amazonlinux | less-debuginfo | < 458-9.amzn2.0.4 | amazonlinux-2 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |