In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal. https://github.com/gwsw/less/commit/a78e1351113cef564d790a730d657a321624d79c http://www.greenwoodsoftware.com/less/news.609.html https://www.openwall.com/lists/oss-security/2023/02/07/7 http://www.openwall.com/lists/oss-security/2023/02/07/7
Created less tracking bugs for this issue: Affects: fedora-36 [bug 2170759] Affects: fedora-37 [bug 2170760]
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:3725 https://access.redhat.com/errata/RHSA-2023:3725
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-46663