Using the “less” Linux command to view the contents of files downloaded from the Internet is a dangerous operation that can lead to remote code execution. Google security engineer Michal Zalewski: Third-party tools that lesspipe relies on have not been designed with malicious input in mind. On many Linux distributions, including Ubuntu and CentOS, it supports many more file types including archives, images and PDF. Users can protect themselves by removing LESSOPEN and LESSCLOSE environment variables if they are set on their Linux systems.”]

