Unrated severityNVD Advisory· Published Jun 28, 2019· Updated Aug 4, 2024
CVE-2019-13012
CVE-2019-13012
Description
The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir, NULL, NULL) and files using g_file_replace_contents (kfsb->file, contents, length, NULL, FALSE, G_FILE_CREATE_REPLACE_DESTINATION, NULL, NULL, NULL). Consequently, it does not properly restrict directory (and file) permissions. Instead, for directories, 0777 permissions are used; for files, default file permissions are used. This is similar to CVE-2019-12450.
Affected products
106- GNOME/GLibdescription
- osv-coords105 versionspkg:rpm/almalinux/accountsservice-develpkg:rpm/almalinux/atkmmpkg:rpm/almalinux/atkmm-develpkg:rpm/almalinux/atkmm-docpkg:rpm/almalinux/cairommpkg:rpm/almalinux/cairomm-develpkg:rpm/almalinux/cairomm-docpkg:rpm/almalinux/chrome-gnome-shellpkg:rpm/almalinux/dleyna-corepkg:rpm/almalinux/dleyna-serverpkg:rpm/almalinux/enchant2pkg:rpm/almalinux/enchant2-develpkg:rpm/almalinux/gaminpkg:rpm/almalinux/gamin-develpkg:rpm/almalinux/geoclue2pkg:rpm/almalinux/geoclue2-demospkg:rpm/almalinux/geoclue2-develpkg:rpm/almalinux/geoclue2-libspkg:rpm/almalinux/geocode-glibpkg:rpm/almalinux/geocode-glib-develpkg:rpm/almalinux/gjspkg:rpm/almalinux/gjs-develpkg:rpm/almalinux/glib2-docpkg:rpm/almalinux/glib2-staticpkg:rpm/almalinux/glibmm24pkg:rpm/almalinux/glibmm24-develpkg:rpm/almalinux/glibmm24-docpkg:rpm/almalinux/gnome-boxespkg:rpm/almalinux/gnome-photospkg:rpm/almalinux/gnome-photos-testspkg:rpm/almalinux/gnome-terminalpkg:rpm/almalinux/gnome-terminal-nautiluspkg:rpm/almalinux/gtk2pkg:rpm/almalinux/gtk2-develpkg:rpm/almalinux/gtk2-devel-docspkg:rpm/almalinux/gtk2-immodulespkg:rpm/almalinux/gtk2-immodule-ximpkg:rpm/almalinux/gtk-docpkg:rpm/almalinux/gtkmm24pkg:rpm/almalinux/gtkmm24-develpkg:rpm/almalinux/gtkmm24-docspkg:rpm/almalinux/gtkmm30pkg:rpm/almalinux/gtkmm30-develpkg:rpm/almalinux/gtkmm30-docpkg:rpm/almalinux/gvfspkg:rpm/almalinux/gvfs-afcpkg:rpm/almalinux/gvfs-afppkg:rpm/almalinux/gvfs-archivepkg:rpm/almalinux/gvfs-clientpkg:rpm/almalinux/gvfs-develpkg:rpm/almalinux/gvfs-fusepkg:rpm/almalinux/gvfs-goapkg:rpm/almalinux/gvfs-gphoto2pkg:rpm/almalinux/gvfs-mtppkg:rpm/almalinux/gvfs-smbpkg:rpm/almalinux/libdazzlepkg:rpm/almalinux/libdazzle-develpkg:rpm/almalinux/libepubgenpkg:rpm/almalinux/libepubgen-develpkg:rpm/almalinux/libsasspkg:rpm/almalinux/libsass-develpkg:rpm/almalinux/libsigc%2B%2B20pkg:rpm/almalinux/libsigc%2B%2B20-develpkg:rpm/almalinux/libsigc%2B%2B20-docpkg:rpm/almalinux/libvisualpkg:rpm/almalinux/libvisual-develpkg:rpm/almalinux/mutter-develpkg:rpm/almalinux/nautiluspkg:rpm/almalinux/nautilus-develpkg:rpm/almalinux/nautilus-extensionspkg:rpm/almalinux/OpenEXR-develpkg:rpm/almalinux/OpenEXR-libspkg:rpm/almalinux/pangommpkg:rpm/almalinux/pangomm-develpkg:rpm/almalinux/pangomm-docpkg:rpm/almalinux/soundtouchpkg:rpm/almalinux/soundtouch-develpkg:rpm/almalinux/valapkg:rpm/almalinux/vala-develpkg:rpm/almalinux/woff2pkg:rpm/almalinux/woff2-develpkg:rpm/opensuse/glib2&distro=openSUSE%20Leap%2015.0pkg:rpm/suse/glib2&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/glib2&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/glib2&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015pkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP4pkg:rpm/suse/glib2&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/glib2&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/glib2&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208
< 0.6.55-1.el8+ 104 more
- (no CPE)range: < 0.6.55-1.el8
- (no CPE)range: < 2.24.2-7.el8
- (no CPE)range: < 2.24.2-7.el8
- (no CPE)range: < 2.24.2-7.el8
- (no CPE)range: < 1.12.0-8.el8
- (no CPE)range: < 1.12.0-8.el8
- (no CPE)range: < 1.12.0-8.el8
- (no CPE)range: < 10.1-7.el8
- (no CPE)range: < 0.6.0-3.el8
- (no CPE)range: < 0.6.0-3.el8
- (no CPE)range: < 2.2.3-3.el8
- (no CPE)range: < 2.2.3-3.el8
- (no CPE)range: < 0.1.10-32.el8
- (no CPE)range: < 0.1.10-32.el8
- (no CPE)range: < 2.5.5-2.el8
- (no CPE)range: < 2.5.5-2.el8
- (no CPE)range: < 2.5.5-2.el8
- (no CPE)range: < 2.5.5-2.el8
- (no CPE)range: < 3.26.0-3.el8
- (no CPE)range: < 3.26.0-3.el8
- (no CPE)range: < 1.56.2-5.el8
- (no CPE)range: < 1.56.2-5.el8
- (no CPE)range: < 2.56.4-9.el8
- (no CPE)range: < 2.56.4-9.el8
- (no CPE)range: < 2.56.0-2.el8
- (no CPE)range: < 2.56.0-2.el8
- (no CPE)range: < 2.56.0-2.el8
- (no CPE)range: < 3.36.5-8.el8
- (no CPE)range: < 3.28.1-4.el8
- (no CPE)range: < 3.28.1-4.el8
- (no CPE)range: < 3.28.3-3.el8
- (no CPE)range: < 3.28.3-3.el8
- (no CPE)range: < 2.24.32-5.el8
- (no CPE)range: < 2.24.32-5.el8
- (no CPE)range: < 2.24.32-5.el8
- (no CPE)range: < 2.24.32-5.el8
- (no CPE)range: < 2.24.32-5.el8
- (no CPE)range: < 1.28-3.el8
- (no CPE)range: < 2.24.5-6.el8
- (no CPE)range: < 2.24.5-6.el8
- (no CPE)range: < 2.24.5-6.el8
- (no CPE)range: < 3.22.2-3.el8
- (no CPE)range: < 3.22.2-3.el8
- (no CPE)range: < 3.22.2-3.el8
- (no CPE)range: < 1.36.2-11.el8
- (no CPE)range: < 1.36.2-11.el8
- (no CPE)range: < 1.36.2-11.el8
- (no CPE)range: < 1.36.2-11.el8
- (no CPE)range: < 1.36.2-11.el8
- (no CPE)range: < 1.36.2-11.el8
- (no CPE)range: < 1.36.2-11.el8
- (no CPE)range: < 1.36.2-11.el8
- (no CPE)range: < 1.36.2-11.el8
- (no CPE)range: < 1.36.2-11.el8
- (no CPE)range: < 1.36.2-11.el8
- (no CPE)range: < 3.28.5-2.el8
- (no CPE)range: < 3.28.5-2.el8
- (no CPE)range: < 0.1.0-3.el8
- (no CPE)range: < 0.1.0-3.el8
- (no CPE)range: < 3.4.5-6.el8
- (no CPE)range: < 3.4.5-6.el8
- (no CPE)range: < 2.10.0-6.el8
- (no CPE)range: < 2.10.0-6.el8
- (no CPE)range: < 2.10.0-6.el8
- (no CPE)range: < 1:0.4.0-25.el8
- (no CPE)range: < 1:0.4.0-25.el8
- (no CPE)range: < 3.32.2-57.el8
- (no CPE)range: < 3.28.1-15.el8
- (no CPE)range: < 3.28.1-15.el8
- (no CPE)range: < 3.28.1-15.el8
- (no CPE)range: < 2.2.0-12.el8
- (no CPE)range: < 2.2.0-12.el8
- (no CPE)range: < 2.40.1-6.el8
- (no CPE)range: < 2.40.1-6.el8
- (no CPE)range: < 2.40.1-6.el8
- (no CPE)range: < 2.0.0-3.el8
- (no CPE)range: < 2.0.0-3.el8
- (no CPE)range: < 0.40.19-2.el8
- (no CPE)range: < 0.40.19-2.el8
- (no CPE)range: < 1.0.2-5.el8
- (no CPE)range: < 1.0.2-5.el8
- (no CPE)range: < 2.54.3-lp150.3.13.1
- (no CPE)range: < 2.48.2-12.15.1
- (no CPE)range: < 2.48.2-12.15.1
- (no CPE)range: < 2.48.2-12.15.1
- (no CPE)range: < 2.48.2-12.15.1
- (no CPE)range: < 2.54.3-4.18.1
- (no CPE)range: < 2.54.3-4.18.1
- (no CPE)range: < 2.54.3-4.18.1
- (no CPE)range: < 2.38.2-7.12.1
- (no CPE)range: < 2.48.2-12.15.1
- (no CPE)range: < 2.48.2-12.15.1
- (no CPE)range: < 2.48.2-12.15.1
- (no CPE)range: < 2.48.2-12.15.1
- (no CPE)range: < 2.48.2-12.15.1
- (no CPE)range: < 2.38.2-7.12.1
- (no CPE)range: < 2.38.2-7.12.1
- (no CPE)range: < 2.48.2-12.15.1
- (no CPE)range: < 2.48.2-12.15.1
- (no CPE)range: < 2.48.2-12.15.1
- (no CPE)range: < 2.48.2-12.15.1
- (no CPE)range: < 2.48.2-12.15.1
- (no CPE)range: < 2.48.2-12.15.1
- (no CPE)range: < 2.48.2-12.15.1
- (no CPE)range: < 2.48.2-12.15.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- lists.opensuse.org/opensuse-security-announce/2019-07/msg00022.htmlmitrevendor-advisoryx_refsource_SUSE
- usn.ubuntu.com/4049-1/mitrevendor-advisoryx_refsource_UBUNTU
- usn.ubuntu.com/4049-2/mitrevendor-advisoryx_refsource_UBUNTU
- bugs.debian.org/cgi-bin/bugreport.cgimitrex_refsource_CONFIRM
- gitlab.gnome.org/GNOME/glib/commit/5e4da714f00f6bfb2ccd6d73d61329c6f3a08429mitrex_refsource_MISC
- gitlab.gnome.org/GNOME/glib/issues/1658mitrex_refsource_MISC
- gitlab.gnome.org/GNOME/glib/merge_requests/450mitrex_refsource_MISC
- lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Emitremailing-listx_refsource_MLIST
- lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Emitremailing-listx_refsource_MLIST
- lists.debian.org/debian-lts-announce/2019/07/msg00029.htmlmitremailing-listx_refsource_MLIST
- lists.debian.org/debian-lts-announce/2019/08/msg00004.htmlmitremailing-listx_refsource_MLIST
- security.netapp.com/advisory/ntap-20190806-0003/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.