CVE-2017-15108
spice-vdagent - security update
7.8
HIGH
CVSS 3.1
EPSS 0.42%
Description
spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.
How to fix CVE-2017-15108
To remediate CVE-2017-15108, upgrade the affected package to a fixed version below.
- Debian/spice-vdagent—upgrade to 0.18.0-1 or later
- —upgrade to 0.17.0-1+deb9u1 or later
Is CVE-2017-15108 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.18.0-1
- from 0, < 0.17.0-1+deb9u1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |