Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Mageia 7: MGASA-2020-0045 Severe: QEMU-Guest Agent Command Injection

mageia
Calendar Grey January 11, 2019
Dist Mageia Esm H88
MGASA-2019-0032 - Updated spice-vdagent package fixes security vulnerability Publication date: 11 Ja
Improperly escaped save directory that is passed to the shell allows local attacker with access to the session the agent runs to inject arbitrary commands to be executed (CVE-2017-...

Summary

Improperly escaped save directory that is passed to the shell allows local attacker with access to the session the agent runs to inject arbitrary commands to be executed (CVE-2017-15108).

References

- https://bugs.mageia.org/show_bug.cgi?id=22564

- - https://www.cve.org/CVERecord?id=CVE-2017-15108

Resolution

SRPMS

- 6/core/spice-vdagent-0.18.0-1.mga6

Publication date: 11 Jan 2019
URL: https://advisories.mageia.org/MGASA-2019-0032.html
Type: security
CVE: CVE-2017-15108

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here