{"id":"CVE-2022-48624","details":"close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.","modified":"2026-08-12T13:33:36.261330Z","published":"2024-02-19T00:00:00Z","related":["ALSA-2024:1610","ALSA-2024:1692","ALSA-2024:4256","SUSE-SU-2024:1189-1","SUSE-SU-2024:1190-1","SUSE-SU-2024:1192-1"],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/48xxx/CVE-2022-48624.json"},"references":[{"type":"WEB","url":"https://github.com/gwsw/less/compare/v605...v606"},{"type":"WEB","url":"https://greenwoodsoftware.com/less/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/48xxx/CVE-2022-48624.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-48624"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20240605-0010/"},{"type":"FIX","url":"https://github.com/gwsw/less/commit/c6ac6de49698be84d264a0c4c0c40bb870b10144"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2024/05/msg00018.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gwsw/less","events":[{"introduced":"0"},{"fixed":"b943c9401956c2bbf3eb09050c6103394801fcbd"},{"fixed":"c6ac6de49698be84d264a0c4c0c40bb870b10144"}],"database_specific":{"cpe":"cpe:2.3:a:greenwoodsoftware:less:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"606"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v605","v603","v602","v601","v600","v598","v597","v596","v595","v594","v592","v591","v590-rel","v590","v586","v585","v584","v581-rel","v581","v583","v582","v580","v579","v578","v577","v576","v575","v574","v573","v572","v571","v570","v569","v568","v567","v566","v564","v563-rel","v563","v562","v561","v560","v559","v558","v557","v556","v555","v554","v553","v551-rel","v551","v550","v549","v548","v547","v546","v545","v544","v543","v542","v541","v540","v539","v538","v537","v536","v535","v534","v533","v532","v531","v530-rel","v530","v529","v527","v526","v525","v524","v523","v522","v521","v520","v519","v518","v517","v516","v515","v514","v513","v512","v511","v510","v509","v508","v507","v506","v505","v504","v503","v502","v501","v500","v499","v497","v496","v495","v494","v493","v492","v491","v490","v489","v488","v487-rel","v487","v486","v485","v484","v483","v482","v481-rel","v481","v480","v479","v478","v477","v476","v475","v474","v473","v471","v470","v469","v468","v467","v466","v465","v464","v463","v462","v461","v460","v459","v458-rel","v458","v457","v456","v455","v454","v453","v452","v451","v450","v449","v448","v447","v446","v445","v444","v443","v442","v441","v440","v439","v438","v437","v436","v435","v434","v433","v432","v431","v430","v429","v428","v427","v426","v425","v424","v423","v422","v421","v420","v419","v418","v417","v416","v415","v414","v413","v412","v411","v410","v409","v408","v407","v406","v405","v404","v403","v402","v401","v400","v399","v398","v397","v396","v395","v394","v382","v381","v380","v379","v378","v377","v376","v375","v374","v373","v372","v371","v370","v368","v367","v366","v365","v364","v363","v362","v361","v360","v359","v358","v357","v356","v355","v354","v353","v352","v351","v350","v349","v348","v347","v346","v345","v344","v343","v342","v341","v340","v339","v338","v337","v336","v335","v334","v332","v330","v329","v328","v327","v326","v325","v324","v323","v322","v321","v320","v319","v318","v317","v316","v315","v314","v313","v312","v311","v310","v309","v308","v307","v306","v305","v304","v303","v302","v301","v300","v299","v298","v297","v296","v295","v294","v293","v292","v291","v290","v289","v288","v287","v286","v285","v284","v283","v282","v281","v280","v279","v278","v277","v276","v275","v274","v273","v272","v271","v270","v269","v268","v267","v266","v265","v264","v263","v262","v261","v260","v259","v258","v257","v256","v255","v254","v253","v252","v251","v250","v247","v245","v244","v243"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-48624.json","vanir_signatures_modified":"2026-08-12T13:33:36Z","vanir_signatures":[{"digest":{"line_hashes":["306021770261279670246813539080188831455","286211567844734036888816066539779932095","337965673169045807242683881453601235425","63612587204719232943457775518519747257","188365998188207895934550425815178729381","26825808796887069506746232562307438123","241187727899275637889378353777800266287","318676316365414321201278515232386691290","23237867540168005579911747706647058481","265489607670972335973402532823414333020"],"threshold":0.9},"id":"CVE-2022-48624-9daa5ede","signature_type":"Line","signature_version":"v1","source":"https://github.com/gwsw/less/commit/c6ac6de49698be84d264a0c4c0c40bb870b10144","target":{"file":"filename.c"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}