First published: Tue Jun 11 2019(Updated: )
daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this server socket and issue D-Bus method calls. (Note that the server socket only accepts a single connection, so the attacker would have to discover the server and connect to the socket before its owner does.) Upstream commits: <a href="https://gitlab.gnome.org/GNOME/gvfs/commit/e3808a1b4042761055b1d975333a8243d67b8bfe">https://gitlab.gnome.org/GNOME/gvfs/commit/e3808a1b4042761055b1d975333a8243d67b8bfe</a> <a href="https://gitlab.gnome.org/GNOME/gvfs/commit/d8c9138bf240975848b1c54db648ec4cd516a48f">https://gitlab.gnome.org/GNOME/gvfs/commit/d8c9138bf240975848b1c54db648ec4cd516a48f</a> <a href="https://gitlab.gnome.org/GNOME/gvfs/commit/70dbfc68a79faac49bd3423e079cb6902522082a">https://gitlab.gnome.org/GNOME/gvfs/commit/70dbfc68a79faac49bd3423e079cb6902522082a</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/gvfs | <1.38.3 | 1.38.3 |
redhat/gvfs | <1.40.2 | 1.40.2 |
redhat/gvfs | <1.41.3 | 1.41.3 |
debian/gvfs | 1.46.2-1 1.50.3-1 1.56.0-2 | |
GNOME libraries | <1.38.3 | |
GNOME libraries | >=1.40.0<1.40.2 | |
GNOME libraries | >=1.41.0<1.41.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12795 is a vulnerability in gvfsd from GNOME gvfs that allows a local attacker to connect to a private D-Bus server socket and issue D-Bus method calls.
CVE-2019-12795 has a severity rating of 7.8 (high).
The affected software of CVE-2019-12795 includes gvfs versions before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3.
To fix CVE-2019-12795, update gvfs to at least version 1.38.3, 1.40.2, or 1.41.3 depending on the affected software version.
You can find more information about CVE-2019-12795 at the following references: - http://www.securityfocus.com/bid/108741 - https://gitlab.gnome.org/GNOME/gvfs/commit/70dbfc68a79faac49bd3423e079cb6902522082a - https://gitlab.gnome.org/GNOME/gvfs/commit/d8c9138bf240975848b1c54db648ec4cd516a48f