Vulnerabilities > CVE-2017-15108

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
spice-space
debian
nessus

Summary

spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.

Vulnerable Configurations

Part Description Count
Application
Spice-Space
1
OS
Debian
1

Nessus

  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-201804-09.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-201804-09 (SPICE VDAgent: Arbitrary command injection) SPICE VDAgent does not properly escape save directory before passing to shell. Impact : A local attacker could execute arbitrary commands. Workaround : There is no known workaround at this time.
    last seen2020-06-01
    modified2020-06-02
    plugin id108930
    published2018-04-10
    reporterThis script is Copyright (C) 2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/108930
    titleGLSA-201804-09 : SPICE VDAgent: Arbitrary command injection
  • NASL familySuSE Local Security Checks
    NASL idOPENSUSE-2018-144.NASL
    descriptionThis update for spice-vdagent provides the following fixes : This security issue was fixed : - CVE-2017-15108: Properly escape save directory that is passed to the shell to prevent local attacker with access to the session the agent runs from injecting arbitrary commands to be executed (bsc#1070724). This non-security issue was fixed : - Implement endian swapping, required for big-endian guests to connect to the spice client successfully. (bsc#1012215) This update was imported from the SUSE:SLE-12-SP2:Update update project.
    last seen2020-06-05
    modified2018-02-08
    plugin id106667
    published2018-02-08
    reporterThis script is Copyright (C) 2018-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/106667
    titleopenSUSE Security Update : spice-vdagent (openSUSE-2018-144)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_SU-2018-0372-1.NASL
    descriptionThis update for spice-vdagent provides the following fixes: This security issue was fixed : - CVE-2017-15108: Properly escape save directory that is passed to the shell to prevent local attacker with access to the session the agent runs from injecting arbitrary commands to be executed (bsc#1070724). The update package also includes non-security fixes. See advisory for details. Note that Tenable Network Security has extracted the preceding description block directly from the SUSE security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id106652
    published2018-02-07
    reporterThis script is Copyright (C) 2018-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/106652
    titleSUSE SLED12 / SLES12 Security Update : spice-vdagent (SUSE-SU-2018:0372-1)
  • NASL familyHuawei Local Security Checks
    NASL idEULEROS_SA-2018-1052.NASL
    descriptionAccording to the version of the spice-vdagent package installed, the EulerOS installation on the remote host is affected by the following vulnerability : - spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.(CVE-2017-15108) Note that Tenable Network Security has extracted the preceding description block directly from the EulerOS security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-05-06
    modified2018-03-20
    plugin id108456
    published2018-03-20
    reporterThis script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/108456
    titleEulerOS 2.0 SP2 : spice-vdagent (EulerOS-SA-2018-1052)
  • NASL familyHuawei Local Security Checks
    NASL idEULEROS_SA-2018-1051.NASL
    descriptionAccording to the version of the spice-vdagent package installed, the EulerOS installation on the remote host is affected by the following vulnerability : - spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.(CVE-2017-15108) Note that Tenable Network Security has extracted the preceding description block directly from the EulerOS security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-05-06
    modified2018-03-20
    plugin id108455
    published2018-03-20
    reporterThis script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/108455
    titleEulerOS 2.0 SP1 : spice-vdagent (EulerOS-SA-2018-1051)