CVE-2017-15108

spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
VendorProductVersion
spice-spacespice-vdagent
𝑥
≤ 0.17.0
debiandebian_linux
9.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
spice-vdagent
bullseye
0.20.0-2
fixed
jessie
no-dsa
wheezy
not-affected
bookworm
0.22.1-3
fixed
sid
0.22.1-4.1
fixed
trixie
0.22.1-4.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
spice-vdagent
noble
Fixed 0.17.0-1ubuntu2
released
mantic
Fixed 0.17.0-1ubuntu2
released
lunar
Fixed 0.17.0-1ubuntu2
released
kinetic
Fixed 0.17.0-1ubuntu2
released
jammy
Fixed 0.17.0-1ubuntu2
released
impish
Fixed 0.17.0-1ubuntu2
released
hirsute
Fixed 0.17.0-1ubuntu2
released
groovy
Fixed 0.17.0-1ubuntu2
released
focal
Fixed 0.17.0-1ubuntu2
released
eoan
Fixed 0.17.0-1ubuntu2
released
disco
Fixed 0.17.0-1ubuntu2
released
cosmic
Fixed 0.17.0-1ubuntu2
released
bionic
Fixed 0.17.0-1ubuntu2
released
artful
ignored
zesty
ignored
xenial
needed
trusty
dne