Lucene search

K
nvd[email protected]NVD:CVE-2022-46663
HistoryFeb 07, 2023 - 9:15 p.m.

CVE-2022-46663

2023-02-0721:15:09
web.nvd.nist.gov
6
gnu less
vulnerability
ansi escape sequences

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.4

Confidence

High

EPSS

0.002

Percentile

64.5%

In GNU Less before 609, crafted data can result in “less -R” not filtering ANSI escape sequences sent to the terminal.

Affected configurations

Nvd
Node
gnulessRange566609
Node
fedoraprojectfedoraMatch37
VendorProductVersionCPE
gnuless*cpe:2.3:a:gnu:less:*:*:*:*:*:*:*:*
fedoraprojectfedora37cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.4

Confidence

High

EPSS

0.002

Percentile

64.5%