Bugzilla – Bug 1070724
VUL-0: CVE-2017-15108: spice-vdagent: Improper validation of xfers->save_dir invdagent_file_xfers_data()
Last modified: 2020-09-16 11:01:04 UTC
CVE-2017-15108 spice-vdagent: Improper validation of xfers->save_dir invdagent_file_xfers_data() could lead to shell command injection References: https://cgit.freedesktop.org/spice/linux/vd_agent/commit/?id=8ba174816d245757e743e636df357910e1d5eb61 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-15108 http://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-15108.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15108
Fix submitted to Factory, SLE-12-SP2:Update and SLE-12:Update.
SUSE-SU-2018:0372-1: An update that solves one vulnerability and has one errata is now available. Category: security (moderate) Bug References: 1012215,1070724 CVE References: CVE-2017-15108 Sources used: SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src): spice-vdagent-0.16.0-8.5.15 SUSE Linux Enterprise Server 12-SP3 (src): spice-vdagent-0.16.0-8.5.15 SUSE Linux Enterprise Server 12-SP2 (src): spice-vdagent-0.16.0-8.5.15 SUSE Linux Enterprise Desktop 12-SP3 (src): spice-vdagent-0.16.0-8.5.15 SUSE Linux Enterprise Desktop 12-SP2 (src): spice-vdagent-0.16.0-8.5.15
openSUSE-SU-2018:0399-1: An update that solves one vulnerability and has one errata is now available. Category: security (moderate) Bug References: 1012215,1070724 CVE References: CVE-2017-15108 Sources used: openSUSE Leap 42.3 (src): spice-vdagent-0.16.0-8.1
released