Back

HIGH

gvfs: improper authorization in daemon/gvfsdaemon.c in gvfsd

Published Jun 11, 2019

Description

daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this server socket and issue D-Bus method calls. (Note that the server socket only accepts a single connection, so the attacker would have to discover the server and connect to the socket before its owner does.)

Affected products

Remediation

Red Hat statement

This issue affects the versions of gvfs as shipped with Red Hat Enterprise Linux 6, 7, and 8. Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This has been rated as having a security impact of Low, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 11, 2019
Updated Aug 4, 2024
Reserved Jun 11, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jun 5, 2019
ENISA EUVD
Assigner mitre
Published Jun 11, 2019
Updated Aug 4, 2024
Exploited since n/a
EUVD-2019-4378