spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2018-01-20T00:00:00Z
Updated: 2024-08-05T19:50:15.989Z
Reserved: 2017-10-08T00:00:00
Link: CVE-2017-15108
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-01-20T00:29:00.407
Modified: 2024-11-21T03:14:05.393
Link: CVE-2017-15108
Redhat
No data.