Improperly escaped save directory that is passed to the shell allows
local attacker with access to the session the agent runs to inject
arbitrary commands to be executed (CVE-2017-15108).
- https://bugs.mageia.org/show_bug.cgi?id=22564
- - https://www.cve.org/CVERecord?id=CVE-2017-15108
- 6/core/spice-vdagent-0.18.0-1.mga6
Get the latest Linux and open source security news straight to your inbox.