less: Denial of service — GLSA 202310-11

A filtering bypass in less may allow denial of service.

Affected packages

sys-apps/less on all architectures
Affected versions < 608-r2
Unaffected versions >= 608-r2

Background

less is a pager and text file viewer.

Description

less suffered from a flaw in its terminal escape sequence handling which made its filtering incomplete.

Impact

Malicious input could clear the terminal output or otherwise manipulate it with faked interactions.

Workaround

There is no known workaround at this time.

Resolution

All less users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=sys-apps/less-608-r2"
 

References

Release date
October 10, 2023

Latest revision
October 10, 2023: 1

Severity
normal

Exploitable
remote

Bugzilla entries