Unrated severityNVD Advisory· Published May 29, 2019· Updated Aug 4, 2024
CVE-2019-12447
CVE-2019-12447
Description
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is not used.
Affected products
21- GNOME/gvfsdescription
- osv-coords20 versionspkg:rpm/almalinux/accountsservice-develpkg:rpm/almalinux/baobabpkg:rpm/almalinux/clutterpkg:rpm/almalinux/clutter-develpkg:rpm/almalinux/clutter-docpkg:rpm/almalinux/gjs-develpkg:rpm/almalinux/gnome-menuspkg:rpm/almalinux/gnome-menus-develpkg:rpm/almalinux/gnome-tweakspkg:rpm/almalinux/mozjs52pkg:rpm/almalinux/mozjs52-develpkg:rpm/almalinux/mozjs60pkg:rpm/almalinux/mozjs60-develpkg:rpm/almalinux/valapkg:rpm/almalinux/vala-develpkg:rpm/opensuse/gvfs&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/gvfs&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/gvfs&distro=openSUSE%20Tumbleweedpkg:rpm/suse/gvfs&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015pkg:rpm/suse/gvfs&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP1
< 0.6.50-8.el8+ 19 more
- (no CPE)range: < 0.6.50-8.el8
- (no CPE)range: < 3.28.0-4.el8
- (no CPE)range: < 1.26.2-8.el8
- (no CPE)range: < 1.26.2-8.el8
- (no CPE)range: < 1.26.2-8.el8
- (no CPE)range: < 1.56.2-4.el8
- (no CPE)range: < 3.13.3-11.el8
- (no CPE)range: < 3.13.3-11.el8
- (no CPE)range: < 3.28.1-7.el8
- (no CPE)range: < 52.9.0-2.el8.alma
- (no CPE)range: < 52.9.0-2.el8.alma
- (no CPE)range: < 60.9.0-4.el8.alma
- (no CPE)range: < 60.9.0-4.el8
- (no CPE)range: < 0.40.19-1.el8
- (no CPE)range: < 0.40.19-1.el8
- (no CPE)range: < 1.34.2.1-lp150.3.10.1
- (no CPE)range: < 1.34.2.1-lp151.6.3.1
- (no CPE)range: < 1.48.1-1.3
- (no CPE)range: < 1.34.2.1-4.13.1
- (no CPE)range: < 1.34.2.1-4.13.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- lists.opensuse.org/opensuse-security-announce/2019-07/msg00008.htmlmitrevendor-advisoryx_refsource_SUSE
- lists.opensuse.org/opensuse-security-announce/2019-07/msg00009.htmlmitrevendor-advisoryx_refsource_SUSE
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FP6BFQUPQRVRRFIYHFWWB6RHJNEB4LGQ/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M2DQVOL5H5BVLXYCEB763DCIYJQ7ZUQ2/mitrevendor-advisoryx_refsource_FEDORA
- usn.ubuntu.com/4053-1/mitrevendor-advisoryx_refsource_UBUNTU
- www.openwall.com/lists/oss-security/2019/07/09/3mitremailing-listx_refsource_MLIST
- gitlab.gnome.org/GNOME/gvfs/commit/d7d362995aa0cb8905c8d5c2a2a4c305d2ffff80mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.