spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.
Metrics
Affected Vendors & Products
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published: 2018-01-20T00:00:00.000Z
Updated: 2024-08-05T19:50:15.989Z
Reserved: 2017-10-08T00:00:00.000Z
Link: CVE-2017-15108
No data.
Status : Modified
Published: 2018-01-20T00:29:00.407
Modified: 2024-11-21T03:14:05.393
Link: CVE-2017-15108
No data.