Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-15108

Опубликовано: 20 янв. 2018
Источник: debian
EPSS Низкий

Описание

spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
spice-vdagentfixed0.18.0-1package
spice-vdagentno-dsajessiepackage
spice-vdagentnot-affectedwheezypackage

Примечания

  • Fixed by: https://cgit.freedesktop.org/spice/linux/vd_agent/commit/?id=8ba174816d245757e743e636df357910e1d5eb61

  • https://bugzilla.redhat.com/show_bug.cgi?id=1510864

EPSS

Процентиль: 34%
0.00419
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 8 лет назад

spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.

CVSS3: 6.5
redhat
почти 9 лет назад

spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.

CVSS3: 7.8
nvd
больше 8 лет назад

spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.

suse-cvrf
больше 8 лет назад

security update for spice-vdagent

suse-cvrf
больше 8 лет назад

security update for spice-vdagent

EPSS

Процентиль: 34%
0.00419
Низкий