A vulnerability has been found in lesspipe which could result in arbitrary code execution.
Package | app-text/lesspipe on all architectures |
---|---|
Affected versions | < 2.06 |
Unaffected versions | >= 2.06 |
lesspipe is a preprocessor for less.
lesspipe has support for parsing Perl storable ("PST") files,
A crafted Perl storable file which is passed into lesspipe could result in arbitrary code execution.
There is no known workaround at this time.
All lesspipe users should update to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=app-text/lesspipe-2.06"
Release date
November 10, 2022
Latest revision
November 10, 2022: 1
Severity
normal
Exploitable
remote
Bugzilla entries