ALT-PU-2018-2332-1
Closed vulnerabilities
Published: 2015-08-18
BDU:2017-02218
Уязвимость обработчика команды «send and receive file» микропрограммного обеспечения эмуляции терминала Picocom, позволяющая нарушителю выполнить произвольную команду
Severity: CRITICAL (9.8)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
Published: 2017-05-28
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2015-9059
picocom before 2.0 has a command injection vulnerability in the 'send and receive file' command because the command line is executed by /bin/sh unsafely.
Severity: CRITICAL (9.8)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
- https://github.com/npat-efault/picocom/commit/1ebc60b20fbe9a02436d5cbbf8951714e749ddb1
- https://github.com/npat-efault/picocom/commit/1ebc60b20fbe9a02436d5cbbf8951714e749ddb1
- [debian-lts-announce] 20200628 [SECURITY] [DLA 2259-1] picocom security update
- [debian-lts-announce] 20200628 [SECURITY] [DLA 2259-1] picocom security update