CVE-2019-12447
Published: 29 May 2019
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is not used.
Priority
CVSS 3 base score: 7.3
Status
Package | Release | Status |
---|---|---|
gvfs Launchpad, Ubuntu, Debian |
bionic |
Released
(1.36.1-0ubuntu1.3.3)
|
cosmic |
Released
(1.38.1-0ubuntu1.3.2)
|
|
disco |
Released
(1.40.1-1ubuntu0.1)
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
xenial |
Not vulnerable
(code not present)
|
|
Patches: upstream: https://gitlab.gnome.org/GNOME/gvfs/commit/daf1163aba229afcfddf0f925aef7e97047e8959 upstream: https://gitlab.gnome.org/GNOME/gvfs/commit/3895e09d784ebec0fbc4614d5c37068736120e1d upstream: https://gitlab.gnome.org/GNOME/gvfs/commit/0f25dea30d01d920443ab72b0c254560ec40e14c (3.30) upstream: https://gitlab.gnome.org/GNOME/gvfs/commit/272e6bdac33309672955e8f8bf1b8f5f1e51fa0a (3.30) upstream: https://gitlab.gnome.org/GNOME/gvfs/commit/cf2f9c4020bbdd895485244b70e9442a80062cbe (3.32) upstream: https://gitlab.gnome.org/GNOME/gvfs/commit/64156459a366d64ab19187455016929b1026189a (3.32) |