PT-2015-3318 · Picocom+1 · Picocom+1
Published
2015-08-18
·
Updated
2020-06-28
·
CVE-2015-9059
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
picocom versions prior to 2.0
Description
The issue is related to a command injection vulnerability in the 'send and receive file' command. This vulnerability arises because the command line is executed by /bin/sh unsafely, allowing an attacker to execute arbitrary commands. The lack of input sanitization measures in the 'send and receive file' command of the Picocom terminal emulation software is the core of the problem. This could enable a remote attacker to execute arbitrary commands using /bin/sh for launching external commands.
Recommendations
For versions prior to 2.0, as a temporary workaround, consider disabling the 'send and receive file' command until a patch is available. Restrict access to the
send and receive file functionality to minimize the risk of exploitation. Update to version 2.0 or later to resolve the issue.Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Picocom