CVE-2019-12449: Medium severity Gnome gvfs vulnerability
Published May 29, 2019
·Updated
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and group ownership during move (and copy with GFILECOPYALLMETADATA) operations from admin:// to file:// URIs, because root privileges are unavailable.
Affected Software
10 affected componentsFixes available
Gnome gvfs>=1.29.4<=1.41.2
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Canonical Ubuntu Linux=19.04
Fedoraproject Fedora=29
Fedoraproject Fedora=30
openSUSE Leap=15.0
openSUSE Leap=15.1
debian/gvfs
1.46.2-11.50.3-11.57.2-21.58.0-21.59.1-1
Remediation
Event History
May 29, 2019
CVE Published
via MITRE·04:16 PM
Data Sourced
via MITRE·04:16 PM
Description
Data Sourced
via NVD·05:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 20, 2026
Data Sourced
via Ubuntu·10:41 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·10:42 PM
Description
Data Sourced
via Debian·10:42 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-12449.
2
What is the severity of CVE-2019-12449?
The severity of CVE-2019-12449 is medium with a CVSS score of 5.7.
3
How does CVE-2019-12449 affect GNOME gvfs?
CVE-2019-12449 affects GNOME gvfs versions 1.29.4 through 1.41.2.
4
What is the impact of CVE-2019-12449?
CVE-2019-12449 allows an attacker to mishandle a file's user and group ownership during move and copy operations, potentially leading to unauthorized access or privilege escalation.
5
Is there a fix for CVE-2019-12449?
Yes, there are updates available for each affected version of GNOME gvfs.