{"id":"CVE-2024-32487","details":"less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.","modified":"2026-08-18T17:26:54.476857Z","published":"2024-04-13T00:00:00Z","related":["ALSA-2024:3513","ALSA-2024:4256","SUSE-SU-2024:1534-1","SUSE-SU-2024:1550-1","SUSE-SU-2024:1598-1","SUSE-SU-2024:1598-2","SUSE-SU-2024:2060-1","SUSE-SU-2025:20007-1","SUSE-SU-2025:20394-1","openSUSE-SU-2025:14862-1"],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32487.json"},"references":[{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2024/04/12/5"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2024/04/13/2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32487.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-32487"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20240605-0009/"},{"type":"FIX","url":"https://github.com/gwsw/less/commit/007521ac3c95bc76e3d59c6dbfe75d06c8075c33"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2024/04/15/1"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2024/05/msg00018.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gwsw/less","events":[{"introduced":"0"},{"fixed":"007521ac3c95bc76e3d59c6dbfe75d06c8075c33"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:greenwoodsoftware:less:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"653"}]}}],"versions":["v653","v651","v650","v649","v648","v647","v646","v644","v643-rel","v643","v642","v641","v640","v639","v636","v635","v634","v633-rel","v633","v632","v631","v630","v629","v628","v627","v626","v625","v624","v623","v621","v620","v619","v618","v617","v616","v608-rel","v608","v607","v605","v603","v602","v601","v600","v598","v597","v596","v595","v594","v592","v591","v590-rel","v590","v586","v585","v584","v581-rel","v581","v583","v582","v580","v579","v578","v577","v576","v575","v574","v573","v572","v571","v570","v569","v568","v567","v566","v564","v563-rel","v563","v562","v561","v560","v559","v558","v557","v556","v555","v554","v553","v551-rel","v551","v550","v549","v548","v547","v546","v545","v544","v543","v542","v541","v540","v539","v538","v537","v536","v535","v534","v533","v532","v531","v530-rel","v530","v529","v527","v526","v525","v524","v523","v522","v521","v520","v519","v518","v517","v516","v515","v514","v513","v512","v511","v510","v509","v508","v507","v506","v505","v504","v503","v502","v501","v500","v499","v497","v496","v495","v494","v493","v492","v491","v490","v489","v488","v487-rel","v487","v486","v485","v484","v483","v482","v481-rel","v481","v480","v479","v478","v477","v476","v475","v474","v473","v471","v470","v469","v468","v467","v466","v465","v464","v463","v462","v461","v460","v459","v458-rel","v458","v457","v456","v455","v454","v453","v452","v451","v450","v449","v448","v447","v446","v445","v444","v443","v442","v441","v440","v439","v438","v437","v436","v435","v434","v433","v432","v431","v430","v429","v428","v427","v426","v425","v424","v423","v422","v421","v420","v419","v418","v417","v416","v415","v414","v413","v412","v411","v410","v409","v408","v407","v406","v405","v404","v403","v402","v401","v400","v399","v398","v397","v396","v395","v394","v382","v381","v380","v379","v378","v377","v376","v375","v374","v373","v372","v371","v370","v368","v367","v366","v365","v364","v363","v362","v361","v360","v359","v358","v357","v356","v355","v354","v353","v352","v351","v350","v349","v348","v347","v346","v345","v344","v343","v342","v341","v340","v339","v338","v337","v336","v335","v334","v332","v330","v329","v328","v327","v326","v325","v324","v323","v322","v321","v320","v319","v318","v317","v316","v315","v314","v313","v312","v311","v310","v309","v308","v307","v306","v305","v304","v303","v302","v301","v300","v299","v298","v297","v296","v295","v294","v293","v292","v291","v290","v289","v288","v287","v286","v285","v284","v283","v282","v281","v280","v279","v278","v277","v276","v275","v274","v273","v272","v271","v270","v269","v268","v267","v266","v265","v264","v263","v262","v261","v260","v259","v258","v257","v256","v255","v254","v253","v252","v251","v250","v247","v245","v244","v243"],"database_specific":{"vanir_signatures_modified":"2026-08-18T17:26:54Z","vanir_signatures":[{"digest":{"length":846,"function_hash":"21512441872404318376774822434280745476"},"id":"CVE-2024-32487-3e056bdc","signature_type":"Function","signature_version":"v1","source":"https://github.com/gwsw/less/commit/007521ac3c95bc76e3d59c6dbfe75d06c8075c33","target":{"function":"shell_quoten","file":"filename.c"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["6392856912888587988469121716084137540","270698381364005912365080033924923909128","318074949332500423466599373294260241169","328415284983022296077022486907155490794","289737217164822785345111873191726688282","189455528938103306586446648766268305176","218584657416246573268543105314978548151","183112455831047898812042513852324344280","189813269534570981535526249696743330997","320490191076196738139528607302830583836","313537205324788312003463297808254168523","71429175339232634504927653181210309974","96387650130909143470870128363097199606","255033481903084783363520326276290220715","151725255370670263930159020310191496177","25140373869608485903155282993232658089","97183714326804796251507833940305662688","149680852007861882086952961165833901061","78485727664940003197033471613650392146","231954030887503870082288013121597790953"],"threshold":0.9},"id":"CVE-2024-32487-902a445c","signature_type":"Line","signature_version":"v1","source":"https://github.com/gwsw/less/commit/007521ac3c95bc76e3d59c6dbfe75d06c8075c33","target":{"file":"filename.c"}}],"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-32487.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}