GNU less 'is _ utf8_well_formed () 'function Remote Buffer Overflow Vulnerability
GNU less 'is _ utf8_well_formed () 'function Remote Buffer Overflow Vulnerability
Release date:
Updated on:
Affected Systems:
GNU less <475
Description:
Bugtraq id: 74159
CVE (CAN) ID: CVE-2014-9488
GNU less is a terminal pager program on Unix/Windows/Unix-like systems. It is used to view file content.
In versions earlier than GNU less 475, The is_utf8_well_formed function has a security vulnerability. Remote attackers trigger out-of-bounds read through malformed UTF-8 characters, which can execute arbitrary code in the context of the affected application.
<* Source: David Walser
*>
Suggestion:
Vendor patch:
GNU
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://advisories.mageia.org/MGASA-2015-0139.html
This article permanently updates the link address: