A vulnerability has been found in lesspipe which could result in arbitrary code execution.
|Package||app-text/lesspipe on all architectures|
|Affected versions||< 2.06|
|Unaffected versions||>= 2.06|
lesspipe is a preprocessor for less.
lesspipe has support for parsing Perl storable ("PST") files,
A crafted Perl storable file which is passed into lesspipe could result in arbitrary code execution.
There is no known workaround at this time.
All lesspipe users should update to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=app-text/lesspipe-2.06"
November 10, 2022
November 10, 2022: 1