CVE-2019-12447: High severity Gnome gvfs vulnerability
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is not used.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-12447.
What is the severity of CVE-2019-12447?
The severity of CVE-2019-12447 is high with a CVSS score of 7.3.
What software is affected by CVE-2019-12447?
GNOME gvfs versions 1.29.4 through 1.41.2 are affected.
How can I fix CVE-2019-12447 on Ubuntu?
To fix CVE-2019-12447 on Ubuntu, update the gvfs package to versions 1.36.1-0ubuntu1.3.3, 1.38.1-0ubuntu1.3.2, or 1.40.1-1ubuntu0.1 depending on your Ubuntu version.
Are there any references for CVE-2019-12447?
Yes, you can find references for CVE-2019-12447 at the following links: [http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00009.html](http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00009.html) and [http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00008.html](http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00008.html).