VDB
GCVE-VVD-MAGEIA-2024-139
GCVE-VVD-MAGEIA-2024-139
Advisory Published
less through 653 allows OS command execution via a newline character in
the name of a file, because quoting is mishandled in filename.c.
Exploitation typically requires use with attacker-controlled file names,
such as the files extracted from an untrusted archive. Exploitation also
requires the LESSOPEN environment variable, but this is set by default
in many common cases. (CVE-2024-32487)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | godot | 0 (affected), 4.2.2-1.mga9 (unaffected) | — |
| Mageia | less | 0 (affected), 632-1.2.mga9 (unaffected), 0 (affected), 632-1.2.mga9 (unaffected) | — |
References
Updated godot packages fix bugs
advisory
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.