Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
197

Debian 8 LTS: DLA-2259-1 Critical: Picocom Command Injection

It was discovered that there was a command injection vulnerability in picocom, a minimal dumb-terminal emulation program. . Package : picocom Version : 1.7-1+deb8u1 CVE ID : CVE-2015-9059 It was discovered that there was a command injection vulnerability in picocom, a minimal dumb-terminal emulation program. For Debian 8 "Jessie", this problem has been fixed in version 1.7-1+deb8u1. We recommend that you upgrade your picocom packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Elevate picocom to rectify command injection vulnerabilities and bolster Debian 8 security measures. Transition to version 1.7-1+deb8u1.. Debian Security, Picocom Update, Command Injection Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 28, 2020 Critical Debian LTS
89

Fedora 25: 2017-ac7fc2fd8c Moderate: Picocom Command Injection Fix

Upgrade to 2.2, fixing CVE-2015-9059. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-ac7fc2fd8c 2017-06-11 16:12:43.870326 --------------------------------------------------------------------------------Name : picocom Product : Fedora 25 Version : 2.2 Release : 2.fc25 URL : https://github.com/npat-efault/picocom Summary : Minimal serial communications program Description : As its name suggests, [picocom] is a minimal dumb-terminal emulation program. It is, in principle, very much like minicom, only it's "pico" instead of "mini"! It was designed to serve as a simple, manual, modem configuration, testing, and debugging tool. It has also served (quite well) as a low-tech "terminal-window" to allow operator intervention in PPP connection scripts (something like the ms-windows "open terminal window before / after dialing" feature). It could also prove useful in many other similar tasks. It is ideal for embedded systems since its memory footprint is minimal (less than 20K, when stripped). --------------------------------------------------------------------------------Update Information: Upgrade to 2.2, fixing CVE-2015-9059 --------------------------------------------------------------------------------References: [ 1 ] Bug #1456399 - CVE-2015-9059 picocom: Command injection in the "send and receive file" command [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1456399 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade picocom' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu 20.04 libxml2 undergoes a crucial security patch to address XSS flaws. Update today for enhanced protection.. Fedora Update, Picocom Security, Command Injection Fix, Software Upgrade. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 11, 2017 Important Fedora
89

Fedora 24: Security Advisory for Picocom 2.2 Command Injection Risk

Upgrade to 2.2, fixing CVE-2015-9059. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-f942f19ff4 2017-06-11 16:12:29.003581 --------------------------------------------------------------------------------Name : picocom Product : Fedora 24 Version : 2.2 Release : 2.fc24 URL : https://github.com/npat-efault/picocom Summary : Minimal serial communications program Description : As its name suggests, [picocom] is a minimal dumb-terminal emulation program. It is, in principle, very much like minicom, only it's "pico" instead of "mini"! It was designed to serve as a simple, manual, modem configuration, testing, and debugging tool. It has also served (quite well) as a low-tech "terminal-window" to allow operator intervention in PPP connection scripts (something like the ms-windows "open terminal window before / after dialing" feature). It could also prove useful in many other similar tasks. It is ideal for embedded systems since its memory footprint is minimal (less than 20K, when stripped). --------------------------------------------------------------------------------Update Information: Upgrade to 2.2, fixing CVE-2015-9059 --------------------------------------------------------------------------------References: [ 1 ] Bug #1456399 - CVE-2015-9059 picocom: Command injection in the "send and receive file" command [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1456399 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade picocom' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Upgrade picocom to version 2.2 on Fedora 24 to enhance security and fix command injection vulnerabilities associated with file operations to stay protected. Fedora Update, Picocom Upgrade, Command Injection, Serial Communication, Fedora Security. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 11, 2017 Important Fedora
197

Debian 7 Wheezy DLA-974-1: Moderate Command Injection Fix for Picocom

It was discovered that there was a command injection vulnerability in picocom, a dumb-terminal emulation program. For Debian 7 "Wheezy", this issue has been fixed in picocom version . Hash: SHA256 Package : picocom Version : 1.7-1+deb7u1 CVE ID : CVE-2015-9059 Debian Bug : #863671 It was discovered that there was a command injection vulnerability in picocom, a dumb-terminal emulation program. For Debian 7 "Wheezy", this issue has been fixed in picocom version 1.7-1+deb7u1. We recommend that you upgrade your picocom packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'` This email address is being protected from spambots. You need JavaScript enabled to view it. / chris-lamb.co.uk `- . Debian 7 Wheezy released update 1.7-1+deb7u1 for picocom, fixing command injection vulnerabilities and enhancing security for terminal communications. Debian Security, Picocom Command Injection, Debian Wheezy Fix. . LinuxSecurity.com Team

Calendar 2 Jun 01, 2017 Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here