Описание
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is not used.
It was discovered that gvfs incorrectly set the ownership of files handled by the admin:// backend. An attacker could abuse this flaw when the destination file of a copy/move operation is handled by the admin:// backend. The attacker would have access to the target files with the ability to read and write them.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | gvfs | Not affected | ||
Red Hat Enterprise Linux 7 | gvfs | Will not fix | ||
Red Hat Enterprise Linux 8 | accountsservice | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | appstream-data | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | baobab | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | clutter | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | evince | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | gdm | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | gjs | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | gnome-boxes | Fixed | RHSA-2020:1766 | 28.04.2020 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.4 Medium
CVSS3
Связанные уязвимости
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is not used.
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is not used.
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gv ...
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is not used.
Уязвимость компонента daemon/gvfsbackendadmin.c подсистемы GVFS среды рабочего стола GNOME операционных систем Linux, позволяющая нарушителю оказать воздействие на целостность, конфиденциальность и доступность защищаемой информации
EPSS
6.4 Medium
CVSS3