SB2015050504 - Buffer overflow in less (Alpine package)
Published: May 5, 2015
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2014-9488)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed UTF-8 characters, which triggers an out-of-bounds read.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=1e95b722c563cb0d9e7bfeacee787d0f2f9fd861
- https://git.alpinelinux.org/aports/commit/?id=447aaed49cd682bda892846139a0ee04a25cb41e
- https://git.alpinelinux.org/aports/commit/?id=092770194c8e16e42adfb28eb07f5e8a789eb9aa
- https://git.alpinelinux.org/aports/commit/?id=5463c1a8b4a387e1c9db804d851e17988ed107ed