PT-2019-2632 · Gnome+7 · Gnome Gvfs+7

Simon Mcvittie

·

Published

2019-05-29

·

Updated

2024-07-31

·

CVE-2019-12795

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GNOME gvfs versions prior to 1.38.3 GNOME gvfs versions 1.40.x prior to 1.40.2 GNOME gvfs versions 1.41.x prior to 1.41.3
Description The issue is related to errors in the authorization procedure of the GVFS subsystem in the GNOME desktop environment for Linux operating systems. A local attacker could connect to the D-Bus server socket and issue D-Bus method calls, potentially allowing them to exploit the vulnerability. The server socket only accepts a single connection, so the attacker would have to discover the server and connect to the socket before its owner does.
Recommendations For versions prior to 1.38.3, update to version 1.38.3 or later. For versions 1.40.x prior to 1.40.2, update to version 1.40.2 or later. For versions 1.41.x prior to 1.41.3, update to version 1.41.3 or later.

Exploit

Fix

Incorrect Default Permissions

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2019:3553
ALT-PU-2019-2363
ALT-PU-2019-2406
BDU:2019-02517
CESA-2019_3553
CVE-2019-12795
DLA-1827-1
MGASA-2019-0214
OPENSUSE-SU-2019:1697-1
OPENSUSE-SU-2019:1699-1
OPENSUSE-SU-2019_1697-1
OPENSUSE-SU-2019_1699-1
OPENSUSE-SU-2024:10838-1
RHSA-2019:3553
RHSA-2019_3553
RLSA-2019:3553
SUSE-SU-2019:1717-1
SUSE-SU-2024:2681-1
SUSE-SU-2024_2681-1
USN-4053-1

Affected Products

Alt Linux
Almalinux
Centos
Gnome Gvfs
Red Hat
Rocky Linux
Suse
Ubuntu