ALT-PU-2018-2332-1
Closed vulnerabilities
                                                                                    Published: 2015-08-18
                                                                                    
                                                                                
                                                                            BDU:2017-02218
Уязвимость обработчика команды «send and receive file» микропрограммного обеспечения эмуляции терминала Picocom, позволяющая нарушителю выполнить произвольную команду
                                                                                        
                                                                                        
                                                                                            Severity: CRITICAL (9.8)
                                                                                        
                                                                                        
                                                                                        
                                                                                        
                                                                                            Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
                                                                                        
                                                                                        
                                                                                    
                                                                                
                                                                                        
                                                                                        
                                                                                            Severity: CRITICAL (10.0)
                                                                                        
                                                                                        
                                                                                        
                                                                                        
                                                                                            Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
                                                                                        
                                                                                        
                                                                                    
                                                                                References:
                                                                        
                                                                        
                                                                    
                                                                                    Published: 2017-05-28
Modified: 2025-04-20
                                                                            Modified: 2025-04-20
CVE-2015-9059
picocom before 2.0 has a command injection vulnerability in the 'send and receive file' command because the command line is executed by /bin/sh unsafely.
                                                                                        
                                                                                        
                                                                                            Severity: CRITICAL (10.0)
                                                                                        
                                                                                        
                                                                                        
                                                                                        
                                                                                            Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
                                                                                        
                                                                                        
                                                                                    
                                                                                
                                                                                        
                                                                                        
                                                                                            Severity: CRITICAL (9.8)
                                                                                        
                                                                                        
                                                                                        
                                                                                        
                                                                                            Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
                                                                                        
                                                                                        
                                                                                    
                                                                                References:
                                                                        - https://github.com/npat-efault/picocom/commit/1ebc60b20fbe9a02436d5cbbf8951714e749ddb1
- https://lists.debian.org/debian-lts-announce/2020/06/msg00030.html
- https://github.com/npat-efault/picocom/commit/1ebc60b20fbe9a02436d5cbbf8951714e749ddb1
- https://lists.debian.org/debian-lts-announce/2020/06/msg00030.html
