[slackware-security] less (SSA:2024-105-01)

Posted on 14 April 2024
Slackware Security

New less packages are available for Slackware 15.0 and -current to
fix a security issue.

Here are the details from the Slackware 15.0 ChangeLog:
patches/packages/less-653-i586-1_slack15.0.txz: Upgraded.
This update patches a security issue:
less through 653 allows OS command execution via a newline character in the
name of a file, because quoting is mishandled in filename.c. Exploitation
typically requires use with attacker-controlled file names, such as the files
extracted from an untrusted archive. Exploitation also requires the LESSOPEN
environment variable, but this is set by default in many common cases.
For more information, see:
(* Security fix *)

Where to find the new packages:

Updated package for Slackware 15.0:

Updated package for Slackware x86_64 15.0:

Updated package for Slackware -current:

Updated package for Slackware x86_64 -current:

Installation instructions:

Upgrade the package as root:
# upgradepkg less-653-i586-1_slack15.0.txz


Slackware Linux Security Team