A flaw was found in gvfs 1.38.1-1. Unprivileged users are not prompted to give password when accessing root owned files.
Upstream issue:
https://gitlab.gnome.org/GNOME/gvfs/issues/355
Upstream patch:
https://gitlab.gnome.org/GNOME/gvfs/mergerequests/31
Directory traversal vulnerability in the gcabfolderextract function in libgcab/gcab-folder.c in gcab 0.4 allows remote attackers to write to arbitrary files via crafted path in a CAB file, as demonstrated by "\tmp\moo."