À la une
Veille
Sécurité
DevOps
Cloud
IA
Self-hosted
Linux
Réseau
Rechercher
⌘K
EN
en direct
CVE-2025-15662 · CVSS 8.6
CVE-2025-50455 · CVSS 9.1
CVE-2025-59172 · CVSS 8.5
CVE-2025-68686 · Fortinet FortiOS
accueil
veille
Gpsd Project
éditeur
Gpsd Project
1
vulnérabilité suivie
1
critiques
9 juillet 2026
dernière publication
cve
Veille des vulnérabilités
identifiant
vulnérabilité
sévérité
publié
CVE-2026-58459
gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.
Gpsd Project Gpsd
Critique
CVSS 9.6
09/07
← Retour à la veille
esc
Tapez au moins deux caractères.
↑
↓
naviguer
↵
ouvrir
esc
fermer