CVE-2017-15108
Summary
| CVE | CVE-2017-15108 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-20 00:29:00 UTC |
| Updated | 2022-10-07 13:25:00 UTC |
| Description | spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| SPICE VDAgent: Arbitrary command injection (GLSA 201804-09) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| spice/linux/vd_agent - spice agent for linux (mirrored from https://gitlab.freedesktop.org/spice/linux/vd_agent) |
CONFIRM |
cgit.freedesktop.org |
Patch, Third Party Advisory |
| [SECURITY] [DLA 2524-1] spice-vdagent security update |
MLIST |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710236 Gentoo Linux SPICE VDAgent Arbitrary command injection Vulnerability (GLSA 201804-09)