Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| spice-vdagent | not-affected | package |
Примечания
https://bugzilla.redhat.com/show_bug.cgi?id=2493580
Связанные уязвимости
CVSS3: 5.3
redhat
2 месяца назад
A flaw was found in spice-vdagent. On macOS and BSD platforms, an unprivileged local user can bypass authentication by connecting to the Unix Domain Socket Client/Server (UDSCS) socket. This allows the unauthorized user to receive host-to-guest messages, including clipboard data and file transfers, inject clipboard data to the SPICE host, and prevent the legitimate agent from functioning.