Mageia 2019-0032: spice-vdagent security update
Summary
Improperly escaped save directory that is passed to the shell allows
local attacker with access to the session the agent runs to inject
arbitrary commands to be executed (CVE-2017-15108).
References
- https://bugs.mageia.org/show_bug.cgi?id=22564
- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15108
Resolution
MGASA-2019-0032 - Updated spice-vdagent package fixes security vulnerability
SRPMS
- 6/core/spice-vdagent-0.18.0-1.mga6