PT-2026-56825 · Gpsd+1 · Gpsd+1
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
gpsd versions prior to 3.27.6
Description
A command injection issue exists in the
gpsprof tool. Attackers who can control the GPS device subtype value can execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title. This occurs because the subtype field, sourced from a DEVICES JSON log entry or NMEA PGRMT sentence, is written into a generated gnuplot program via a set title statement where only double-quote characters are escaped. The execution happens as the user running gnuplot when the plot is rendered through the gpsprof and gnuplot workflow.Recommendations
Update to the version containing commit 4c06658 or newer.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rocky Linux
Gpsd