PT-2015-3318 · Picocom+1 · Picocom+1

Published

2015-08-18

·

Updated

2020-06-28

·

CVE-2015-9059

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions picocom versions prior to 2.0
Description The issue is related to a command injection vulnerability in the 'send and receive file' command. This vulnerability arises because the command line is executed by /bin/sh unsafely, allowing an attacker to execute arbitrary commands. The lack of input sanitization measures in the 'send and receive file' command of the Picocom terminal emulation software is the core of the problem. This could enable a remote attacker to execute arbitrary commands using /bin/sh for launching external commands.
Recommendations For versions prior to 2.0, as a temporary workaround, consider disabling the 'send and receive file' command until a patch is available. Restrict access to the send and receive file functionality to minimize the risk of exploitation. Update to version 2.0 or later to resolve the issue.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2332
BDU:2017-02218
CVE-2015-9059
DLA-2259-1
DLA-974-1

Affected Products

Alt Linux
Picocom