The vulnerability is in less-the-complete-system. More doesn't even have the ability to pipe its input through random shell scripts that call exploitable programs, AFAIK.
The problem is parsing complex file formats in unsafe programming languages, and any system which does that will be vulnerable.
The problem is parsing complex file formats in unsafe programming languages, and any system which does that will be vulnerable.