REDHAT-BUG-2526784: Medium severity gvfs vulnerability
A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer, causing the operation to access past the intended boundaries. This issue allows a malicious server to overflow a heap buffer and crash the gvfsd-afp process, resulting in a denial of service. This vulnerability affects all gvfs versions and is fixed in version 1.60.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
gvfs (AFP backend / gvfsd-afp)to a version that resolves this vulnerability.Fixed in 1.60.2
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems using gvfs with the AFP backend are exposed when they mount an AFP share from a malicious server. The issue affects all gvfs versions before the fix in 1.60.2.
What does an attacker need to exploit it?
An attacker needs to operate or control an AFP server that a client mounts. The malicious server can send a reply length larger than the client-requested buffer size during the DSI read path.
What is the impact of successful exploitation?
Successful exploitation can overflow a heap buffer and crash the gvfsd-afp process, causing a denial of service.
How can the issue be remediated?
Update gvfs to version 1.60.2 or later. Until updates are available, avoid mounting AFP shares from untrusted or potentially malicious servers.