A buffer overflow flaw was found in the way minicom before version 2.7.1 handled VT100 escape sequences. A malicious terminal device could potentially use this flaw to crash minicom, or execute arbitrary code in the context of the minicom process.
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade minicom | Apr 24, 2017 | Apr 21, 2017 |
| Gentoo Linux | — | Upgrade net-dialup/minicom. | Oct 30, 2017 | Jun 6, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade minicom | Feb 22, 2021 | Jul 11, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade minicom | Jan 20, 2021 | Jul 11, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade minicom | Feb 3, 2021 | Jul 11, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 11, 2018 |
| Suse | — | Upgrade minicomUpgrade minicom-lang | Apr 21, 2017 | Apr 21, 2017 |
| Ubuntu | — | Upgrade minicom | Nov 19, 2024 | Jul 11, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub