CVE-2019-12449 log
Source |
|
Severity | Medium |
Remote | No |
Type | Privilege escalation |
Description | An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and group ownership during move (and copy with G_FILE_COPY_ALL_METADATA) operations from admin:// to file:// URIs, because root privileges are unavailable. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-1007 | gvfs | 1.40.1-1 | 1.40.2-1 | Medium | Fixed |
References |
---|
https://gitlab.gnome.org/GNOME/gvfs/commit/d5dfd823c94045488aef8727c553f1e0f7666b90 https://www.openwall.com/lists/oss-security/2019/07/09/3 |