CVE-2014-9488
Publication date 14 April 2015
Last updated 24 July 2024
Ubuntu priority
The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed UTF-8 characters, which triggers an out-of-bounds read.
Status
Package | Ubuntu Release | Status |
---|---|---|
less | ||
14.04 LTS trusty |
Not affected
|
|
Notes
tyhicks
Hanno's blog post has been updated to say that less 458 is not affected I've verified that no stable releases are affected via the reproducers on Hanno's blog post and valgrind
Patch details
Package | Patch details |
---|---|
less |