Lucene search

K
redosRedosROS-20230210-01
HistoryFeb 10, 2023 - 12:00 a.m.

ROS-20230210-01

2023-02-1000:00:00
redos.red-soft.ru
53
gnu less
unix
vulnerability
remote
privilege escalation
ansi control sequences

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

64.5%

The vulnerability of the GNU Less utility for UNIX-like UNIX text terminals is due to the fact that calling “less
-R” will not filter ANSI control sequences sent to the terminal. Exploitation
of the vulnerability could allow an attacker acting remotely to escalate his privileges on the system

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64less< 608-1UNKNOWN

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

64.5%