Bugzilla – Bug 1041155
VUL-0: CVE-2015-9059: picocom: command injection vulnerability in the 'send andreceive file' command
Last modified: 2017-05-29 22:12:23 UTC
CVE-2015-9059 picocom before 2.0 has a command injection vulnerability in the 'send and receive file' command because the command line is executed by /bin/sh unsafely. No maintainer, you did the last change. Please assign to security-team if you don't want to take this. Thanks References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-9059 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-9059 https://github.com/npat-efault/picocom/commit/1ebc60b20fbe9a02436d5cbbf8951714e749ddb1