{"api_version":"1","generated_at":"2026-07-23T10:29:22+00:00","cve":"CVE-2017-15108","urls":{"html":"https://cve.report/CVE-2017-15108","api":"https://cve.report/api/cve/CVE-2017-15108.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-15108","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-15108"},"summary":{"title":"CVE-2017-15108","description":"spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2018-01-20 00:29:00","updated_at":"2022-10-07 13:25:00"},"problem_types":["CWE-78"],"metrics":[],"references":[{"url":"https://security.gentoo.org/glsa/201804-09","name":"GLSA-201804-09","refsource":"GENTOO","tags":[],"title":"SPICE VDAgent: Arbitrary command injection (GLSA 201804-09) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://cgit.freedesktop.org/spice/linux/vd_agent/commit/?id=8ba174816d245757e743e636df357910e1d5eb61","name":"https://cgit.freedesktop.org/spice/linux/vd_agent/commit/?id=8ba174816d245757e743e636df357910e1d5eb61","refsource":"CONFIRM","tags":["Patch","Third Party Advisory"],"title":"spice/linux/vd_agent - spice agent for linux  (mirrored from https://gitlab.freedesktop.org/spice/linux/vd_agent)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2021/01/msg00012.html","name":"[debian-lts-announce] 20210113 [SECURITY] [DLA 2524-1] spice-vdagent security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 2524-1] spice-vdagent security update","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-15108","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-15108","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"15108","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"15108","vulnerable":"1","versionEndIncluding":"0.17.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"spice-space","cpe5":"spice-vdagent","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2017-15108","qid":"710236","title":"Gentoo Linux SPICE VDAgent Arbitrary command injection Vulnerability (GLSA 201804-09)"}]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2017-15108","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-78","cweId":"CWE-78"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Red Hat, Inc.","product":{"product_data":[{"product_name":"spice-vdagent","version":{"version_data":[{"version_affected":"=","version_value":"up to and including 0.17.0"}]}}]}}]}},"references":{"reference_data":[{"url":"https://cgit.freedesktop.org/spice/linux/vd_agent/commit/?id=8ba174816d245757e743e636df357910e1d5eb61","refsource":"MISC","name":"https://cgit.freedesktop.org/spice/linux/vd_agent/commit/?id=8ba174816d245757e743e636df357910e1d5eb61"},{"url":"https://lists.debian.org/debian-lts-announce/2021/01/msg00012.html","refsource":"MISC","name":"https://lists.debian.org/debian-lts-announce/2021/01/msg00012.html"},{"url":"https://security.gentoo.org/glsa/201804-09","refsource":"MISC","name":"https://security.gentoo.org/glsa/201804-09"}]}},"nvd":{"publishedDate":"2018-01-20 00:29:00","lastModifiedDate":"2022-10-07 13:25:00","problem_types":["CWE-78"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":4.6},"severity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:spice-space:spice-vdagent:*:*:*:*:*:*:*:*","versionEndIncluding":"0.17.0","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"15108","Ordinal":"112610","Title":"CVE-2017-15108","CVE":"CVE-2017-15108","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"15108","Ordinal":"1","NoteData":"spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"15108","Ordinal":"2","NoteData":"2018-01-19","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"15108","Ordinal":"3","NoteData":"2021-01-13","Type":"Other","Title":"Modified"}]}}}