Описание
A flaw was found in spice-vdagent. On macOS and BSD platforms, an unprivileged local user can bypass authentication by connecting to the Unix Domain Socket Client/Server (UDSCS) socket. This allows the unauthorized user to receive host-to-guest messages, including clipboard data and file transfers, inject clipboard data to the SPICE host, and prevent the legitimate agent from functioning.
Отчет
Red Hat products are not affected by this CVE as the vulnerable code is not present in Red Hat's shipped versions of spice-vdagent.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | spice-vdagent | Not affected | ||
| Red Hat Enterprise Linux 6 | spice-vdagent | Not affected | ||
| Red Hat Enterprise Linux 7 | spice-vdagent | Not affected | ||
| Red Hat Enterprise Linux 8 | mingw-spice-vdagent | Not affected | ||
| Red Hat Enterprise Linux 8 | spice-vdagent | Not affected | ||
| Red Hat Enterprise Linux 9 | spice-vdagent | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=2493580spice-vdagent: Authentication bypass on macOS/BSD due to dummy session info
5.3 Medium
CVSS3
Связанные уязвимости
5.3 Medium
CVSS3