Описание
[Unknown description]
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | see notes |
| esm-apps-legacy/xenial | not-affected | see notes |
| esm-infra/bionic | not-affected | see notes |
| esm-infra/focal | not-affected | see notes |
| jammy | not-affected | see notes |
| noble | not-affected | see notes |
| questing | ignored | end of life, was not-affected (see notes |
| resolute | not-affected | see notes |
| upstream | not-affected | debian: MacOS/BSD specific |
Показывать по
10
Ссылки на источники
Связанные уязвимости
CVSS3: 5.3
redhat
2 месяца назад
A flaw was found in spice-vdagent. On macOS and BSD platforms, an unprivileged local user can bypass authentication by connecting to the Unix Domain Socket Client/Server (UDSCS) socket. This allows the unauthorized user to receive host-to-guest messages, including clipboard data and file transfers, inject clipboard data to the SPICE host, and prevent the legitimate agent from functioning.