USN-5848-1: less vulnerability
9 February 2023
Use of less could result in a denial of service
Releases
Packages
- less - pager program similar to more
Details
David Leadbeater discovered that less was not properly handling escape
sequences when displaying raw control characters. A maliciously formed
OSC 8 hyperlink could possibly be used by an attacker to cause a denial of
service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.10
Ubuntu 22.04
In general, a standard system update will make all the necessary changes.