Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rx22-vq3w-89rg

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.

spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.

EPSS

Процентиль: 35%
0.00419
Низкий

7.8 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 8 лет назад

spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.

CVSS3: 6.5
redhat
почти 9 лет назад

spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.

CVSS3: 7.8
nvd
больше 8 лет назад

spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.

CVSS3: 7.8
debian
больше 8 лет назад

spice-vdagent up to and including 0.17.0 does not properly escape save ...

suse-cvrf
больше 8 лет назад

security update for spice-vdagent

EPSS

Процентиль: 35%
0.00419
Низкий

7.8 High

CVSS3

Дефекты

CWE-78