All errata/sisyphus/ALT-PU-2018-2332-1
ALT-PU-2018-2332-1

Package update picocom in branch sisyphus

Version3.1-alt2
Published2018-09-17
Max severityCRITICAL
Severity:

Closed issues (2)

BDU:2017-02218
CRITICAL9.8

Уязвимость обработчика команды «send and receive file» микропрограммного обеспечения эмуляции терминала Picocom, позволяющая нарушителю выполнить произвольную команду

Published: 2017-10-11Modified: 2021-03-23
CVSS 3.xCRITICAL 9.8
CVSS:3.x/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.0CRITICAL 10.0
CVSS:2.0/AV:N/AC:L/Au:N/C:C/I:C/A:C
References
CVE-2015-9059
CRITICAL9.8

picocom before 2.0 has a command injection vulnerability in the 'send and receive file' command because the command line is executed by /bin/sh unsafely.

Published: 2017-05-28Modified: 2025-04-20
CVSS 2.0CRITICAL 10.0
CVSS:2.0/AV:N/AC:L/Au:N/C:C/I:C/A:C
CVSS 3.xCRITICAL 9.8
CVSS:3.x/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H