spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2524-1 | spice-vdagent security update |
EUVD |
EUVD-2017-6573 | spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T19:50:15.989Z
Reserved: 2017-10-08T00:00:00
Link: CVE-2017-15108
No data.
Status : Modified
Published: 2018-01-20T00:29:00.407
Modified: 2024-11-21T03:14:05.393
Link: CVE-2017-15108
No data.
OpenCVE Enrichment
No data.
Debian DLA
EUVD