gvfs: improper authorization in daemon/gvfsdaemon.c in gvfsd
Published Jun 11, 2019
7.8
HIGHCVSS 3.0
EPSS 0.39%
Description
daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this server socket and issue D-Bus method calls. (Note that the server socket only accepts a single connection, so the attacker would have to discover the server and connect to the socket before its owner does.)
Affected products
No data.
No data.
Red Hat Enterprise Linux 8
SDL-0:1.2.15-35.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
SDL-0:1.2.15-35.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
accountsservice-0:0.6.50-7.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
accountsservice-0:0.6.50-7.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
appstream-data-0:8-20190805.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
appstream-data-0:8-20190805.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
baobab-0:3.28.0-2.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
baobab-0:3.28.0-2.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
chrome-gnome-shell-0:10.1-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
chrome-gnome-shell-0:10.1-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
evince-0:3.28.4-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
evince-0:3.28.4-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
file-roller-0:3.28.1-2.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
file-roller-0:3.28.1-2.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gdk-pixbuf2-0:2.36.12-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gdk-pixbuf2-0:2.36.12-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gdm-1:3.28.3-22.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gdm-1:3.28.3-22.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gjs-0:1.56.2-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gjs-0:1.56.2-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-control-center-0:3.28.2-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-control-center-0:3.28.2-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-desktop3-0:3.32.2-1.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-desktop3-0:3.32.2-1.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-remote-desktop-0:0.1.6-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-remote-desktop-0:0.1.6-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-settings-daemon-0:3.32.0-4.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-settings-daemon-0:3.32.0-4.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-shell-0:3.32.2-9.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-shell-0:3.32.2-9.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-shell-extensions-0:3.32.1-10.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-shell-extensions-0:3.32.1-10.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-software-0:3.30.6-2.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-software-0:3.30.6-2.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-tweaks-0:3.28.1-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-tweaks-0:3.28.1-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gsettings-desktop-schemas-0:3.32.0-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gsettings-desktop-schemas-0:3.32.0-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gtk3-0:3.22.30-4.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gtk3-0:3.22.30-4.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gvfs-0:1.36.2-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gvfs-0:1.36.2-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
mozjs60-0:60.9.0-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
mozjs60-0:60.9.0-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
mutter-0:3.32.2-10.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
mutter-0:3.32.2-10.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
nautilus-0:3.28.1-10.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
nautilus-0:3.28.1-10.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
pango-0:1.42.4-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
pango-0:1.42.4-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
pidgin-0:2.13.0-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
pidgin-0:2.13.0-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
plymouth-0:0.9.3-15.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
plymouth-0:0.9.3-15.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
wayland-protocols-0:1.17-1.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
wayland-protocols-0:1.17-1.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
webkit2gtk3-0:2.24.3-1.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
webkit2gtk3-0:2.24.3-1.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 6
gvfs
Out of support scope
Red Hat Enterprise Linux 7
gvfs
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | SDL-0:1.2.15-35.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | SDL-0:1.2.15-35.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | accountsservice-0:0.6.50-7.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | accountsservice-0:0.6.50-7.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | appstream-data-0:8-20190805.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | appstream-data-0:8-20190805.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | baobab-0:3.28.0-2.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | baobab-0:3.28.0-2.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | chrome-gnome-shell-0:10.1-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | chrome-gnome-shell-0:10.1-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | evince-0:3.28.4-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | evince-0:3.28.4-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | file-roller-0:3.28.1-2.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | file-roller-0:3.28.1-2.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gdk-pixbuf2-0:2.36.12-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gdk-pixbuf2-0:2.36.12-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gdm-1:3.28.3-22.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gdm-1:3.28.3-22.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gjs-0:1.56.2-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gjs-0:1.56.2-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-control-center-0:3.28.2-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-control-center-0:3.28.2-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-desktop3-0:3.32.2-1.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-desktop3-0:3.32.2-1.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-remote-desktop-0:0.1.6-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-remote-desktop-0:0.1.6-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-settings-daemon-0:3.32.0-4.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-settings-daemon-0:3.32.0-4.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-shell-0:3.32.2-9.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-shell-0:3.32.2-9.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-shell-extensions-0:3.32.1-10.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-shell-extensions-0:3.32.1-10.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-software-0:3.30.6-2.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-software-0:3.30.6-2.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-tweaks-0:3.28.1-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-tweaks-0:3.28.1-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gsettings-desktop-schemas-0:3.32.0-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gsettings-desktop-schemas-0:3.32.0-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gtk3-0:3.22.30-4.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gtk3-0:3.22.30-4.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gvfs-0:1.36.2-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gvfs-0:1.36.2-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | mozjs60-0:60.9.0-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | mozjs60-0:60.9.0-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | mutter-0:3.32.2-10.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | mutter-0:3.32.2-10.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | nautilus-0:3.28.1-10.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | nautilus-0:3.28.1-10.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | pango-0:1.42.4-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | pango-0:1.42.4-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | pidgin-0:2.13.0-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | pidgin-0:2.13.0-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | plymouth-0:0.9.3-15.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | plymouth-0:0.9.3-15.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | wayland-protocols-0:1.17-1.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | wayland-protocols-0:1.17-1.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | webkit2gtk3-0:2.24.3-1.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | webkit2gtk3-0:2.24.3-1.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 6 | gvfs | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | gvfs | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of gvfs as shipped with Red Hat Enterprise Linux 6, 7, and 8. Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This has been rated as having a security impact of Low, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
References (16)
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00008.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00009.html vendor-advisoryx_refsource_SUSE
- http://www.securityfocus.com/bid/108741 vdb-entryx_refsource_BID
- https://access.redhat.com/errata/RHSA-2019:3553 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-12795 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1726505 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-4378 Advisory
- https://gitlab.gnome.org/GNOME/gvfs/commit/70dbfc68a79faac49bd3423e079cb6902522082a x_refsource_MISCPatchVendor Advisory
- https://gitlab.gnome.org/GNOME/gvfs/commit/d8c9138bf240975848b1c54db648ec4cd516a48f x_refsource_MISCPatchVendor Advisory
- https://gitlab.gnome.org/GNOME/gvfs/commit/e3808a1b4042761055b1d975333a8243d67b8bfe x_refsource_MISCPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/06/msg00014.html mailing-listx_refsource_MLIST
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FP6BFQUPQRVRRFIYHFWWB6RHJNEB4LGQ/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M2DQVOL5H5BVLXYCEB763DCIYJQ7ZUQ2/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-12795
- https://usn.ubuntu.com/4053-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2019-12795
Change history (0)
No recorded changes yet.