Candidate: CVE-2017-15108 PublicDate: 2018-01-20 00:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15108 Description: spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed. Ubuntu-Description: Notes: Bugs: https://bugzilla.redhat.com/show_bug.cgi?id=1510864 Priority: medium Discovered-by: Seth Arnold Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_spice-vdagent: upstream: https://cgit.freedesktop.org/spice/linux/vd_agent/commit/?id=8ba174816d245757e743e636df357910e1d5eb61 upstream_spice-vdagent: pending precise/esm_spice-vdagent: DNE trusty_spice-vdagent: ignored (reached end-of-life) trusty/esm_spice-vdagent: DNE (trusty was needed) xenial_spice-vdagent: ignored (end of standard support, was needed) zesty_spice-vdagent: ignored (reached end-of-life) artful_spice-vdagent: ignored (reached end-of-life) bionic_spice-vdagent: released (0.17.0-1ubuntu2) cosmic_spice-vdagent: released (0.17.0-1ubuntu2) disco_spice-vdagent: released (0.17.0-1ubuntu2) eoan_spice-vdagent: released (0.17.0-1ubuntu2) focal_spice-vdagent: released (0.17.0-1ubuntu2) groovy_spice-vdagent: released (0.17.0-1ubuntu2) hirsute_spice-vdagent: released (0.17.0-1ubuntu2) impish_spice-vdagent: released (0.17.0-1ubuntu2) jammy_spice-vdagent: released (0.17.0-1ubuntu2) devel_spice-vdagent: released (0.17.0-1ubuntu2)