Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-12795

Опубликовано: 05 июн. 2019
Источник: redhat
CVSS3: 4.5
EPSS Низкий

Описание

daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this server socket and issue D-Bus method calls. (Note that the server socket only accepts a single connection, so the attacker would have to discover the server and connect to the socket before its owner does.)

Отчет

This issue affects the versions of gvfs as shipped with Red Hat Enterprise Linux 6, 7, and 8. Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This has been rated as having a security impact of Low, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gvfsOut of support scope
Red Hat Enterprise Linux 7gvfsFix deferred
Red Hat Enterprise Linux 8accountsserviceFixedRHSA-2019:355305.11.2019
Red Hat Enterprise Linux 8appstream-dataFixedRHSA-2019:355305.11.2019
Red Hat Enterprise Linux 8baobabFixedRHSA-2019:355305.11.2019
Red Hat Enterprise Linux 8chrome-gnome-shellFixedRHSA-2019:355305.11.2019
Red Hat Enterprise Linux 8evinceFixedRHSA-2019:355305.11.2019
Red Hat Enterprise Linux 8file-rollerFixedRHSA-2019:355305.11.2019
Red Hat Enterprise Linux 8gdk-pixbuf2FixedRHSA-2019:355305.11.2019
Red Hat Enterprise Linux 8gdmFixedRHSA-2019:355305.11.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-285
https://bugzilla.redhat.com/show_bug.cgi?id=1726505gvfs: improper authorization in daemon/gvfsdaemon.c in gvfsd

EPSS

Процентиль: 14%
0.00046
Низкий

4.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 6 лет назад

daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this server socket and issue D-Bus method calls. (Note that the server socket only accepts a single connection, so the attacker would have to discover the server and connect to the socket before its owner does.)

CVSS3: 7.8
nvd
около 6 лет назад

daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this server socket and issue D-Bus method calls. (Note that the server socket only accepts a single connection, so the attacker would have to discover the server and connect to the socket before its owner does.)

CVSS3: 7.8
debian
около 6 лет назад

daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x bef ...

suse-cvrf
11 месяцев назад

Security update for gvfs

github
около 3 лет назад

daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this server socket and issue D-Bus method calls. (Note that the server socket only accepts a single connection, so the attacker would have to discover the server and connect to the socket before its owner does.)

EPSS

Процентиль: 14%
0.00046
Низкий

4.5 Medium

CVSS3