PT-2019-2632 · Gnome+7 · Gnome Gvfs+7

Simon Mcvittie

·

Publicado

2019-05-29

·

Atualizado

2024-07-31

·

CVE-2019-12795

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GNOME gvfs versions prior to 1.38.3 GNOME gvfs versions 1.40.x prior to 1.40.2 GNOME gvfs versions 1.41.x prior to 1.41.3
Description The issue is related to errors in the authorization procedure of the GVFS subsystem in the GNOME desktop environment for Linux operating systems. A local attacker could connect to the D-Bus server socket and issue D-Bus method calls, potentially allowing them to exploit the vulnerability. The server socket only accepts a single connection, so the attacker would have to discover the server and connect to the socket before its owner does.
Recommendations For versions prior to 1.38.3, update to version 1.38.3 or later. For versions 1.40.x prior to 1.40.2, update to version 1.40.2 or later. For versions 1.41.x prior to 1.41.3, update to version 1.41.3 or later.

Exploit

Correção

Incorrect Default Permissions

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2019:3553
ALT-PU-2019-2363
ALT-PU-2019-2406
BDU:2019-02517
CESA-2019_3553
CVE-2019-12795
DLA-1827-1
MGASA-2019-0214
OPENSUSE-SU-2019:1697-1
OPENSUSE-SU-2019:1699-1
OPENSUSE-SU-2019_1697-1
OPENSUSE-SU-2019_1699-1
OPENSUSE-SU-2024:10838-1
RHSA-2019:3553
RHSA-2019_3553
RLSA-2019:3553
SUSE-SU-2019:1717-1
SUSE-SU-2024:2681-1
SUSE-SU-2024_2681-1
USN-4053-1

Produtos afetados

Alt Linux
Almalinux
Centos
Gnome Gvfs
Red Hat
Rocky Linux
Suse
Ubuntu