From 6957f5c65b02bba533954eabc0b62f5de36be206 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Tue, 10 Apr 2018 17:26:49 +0100 Subject: gentoo resync : 10.04.2018 --- metadata/glsa/glsa-201804-09.xml | 50 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 50 insertions(+) create mode 100644 metadata/glsa/glsa-201804-09.xml (limited to 'metadata/glsa/glsa-201804-09.xml') diff --git a/metadata/glsa/glsa-201804-09.xml b/metadata/glsa/glsa-201804-09.xml new file mode 100644 index 000000000000..ab4be111389b --- /dev/null +++ b/metadata/glsa/glsa-201804-09.xml @@ -0,0 +1,50 @@ + + + + SPICE VDAgent: Arbitrary command injection + A vulnerability in SPICE VDAgent could allow local attackers to + execute arbitrary commands. + + spice,vdagent + 2018-04-08 + 2018-04-08 + 650020 + local + + + 0.17.0_p20180319 + 0.17.0_p20180319 + + + +

Provides a complete open source solution for remote access to virtual + machines in a seamless way so you can play videos, record audio, share + USB devices and share folders without complications. +

+
+ +

SPICE VDAgent does not properly escape save directory before passing to + shell. +

+
+ +

A local attacker could execute arbitrary commands.

+
+ +

There is no known workaround at this time.

+
+ +

All SPICE VDAgent users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose + ">=app-emulation/spice-vdagent-0.17.0_p20180319" + +
+ + CVE-2017-15108 + + b-man + b-man +
-- cgit v1.2.3