Описание
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and group ownership during move (and copy with G_FILE_COPY_ALL_METADATA) operations from admin:// to file:// URIs, because root privileges are unavailable.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | gvfs | Not affected | ||
Red Hat Enterprise Linux 7 | gvfs | Will not fix | ||
Red Hat Enterprise Linux 8 | accountsservice | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | appstream-data | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | baobab | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | clutter | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | evince | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | gdm | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | gjs | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | gnome-boxes | Fixed | RHSA-2020:1766 | 28.04.2020 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.8 Medium
CVSS3
Связанные уязвимости
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and group ownership during move (and copy with G_FILE_COPY_ALL_METADATA) operations from admin:// to file:// URIs, because root privileges are unavailable.
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and group ownership during move (and copy with G_FILE_COPY_ALL_METADATA) operations from admin:// to file:// URIs, because root privileges are unavailable.
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gv ...
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and group ownership during move (and copy with G_FILE_COPY_ALL_METADATA) operations from admin:// to file:// URIs, because root privileges are unavailable.
Уязвимость компонента daemon/gvfsbackendadmin.c подсистемы GVFS среды рабочего стола GNOME операционных систем Linux, позволяющая нарушителю оказать воздействие на целостность, конфиденциальность и доступность защищаемой информации
EPSS
4.8 Medium
CVSS3