spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published: 2018-01-20T00:00:00Z
Updated: 2024-08-05T19:50:15.989Z
Reserved: 2017-10-08T00:00:00
Link: CVE-2017-15108

No data.

Status : Modified
Published: 2018-01-20T00:29:00.407
Modified: 2024-11-21T03:14:05.393
Link: CVE-2017-15108

No data.