High severity7.0OSV Advisory· Published Mar 25, 2019· Updated Jun 17, 2026
CVE-2019-3827
CVE-2019-3827
Description
An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious programs running under privileges of users belonging to the wheel group to further escalate its privileges by modifying system files without user's knowledge. Successful exploitation requires uncommon system configuration.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
61.10.0, 1.11.3, 1.11.4, …+ 2 more
- (no CPE)range: 1.10.0, 1.11.3, 1.11.4, …
- cpe:2.3:a:gnome:gvfs:*:*:*:*:*:*:*:*range: <1.39.4
- (no CPE)range: <1.39.4
- osv-coords3 versionspkg:rpm/opensuse/gvfs&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/gvfs&distro=openSUSE%20Tumbleweedpkg:rpm/suse/gvfs&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015
< 1.34.2.1-lp150.3.6.1+ 2 more
- (no CPE)range: < 1.34.2.1-lp150.3.6.1
- (no CPE)range: < 1.48.1-1.3
- (no CPE)range: < 1.34.2.1-4.6.1
Patches
Vulnerability mechanics
References
4- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- gitlab.gnome.org/GNOME/gvfs/merge_requests/31nvdPatchVendor Advisory
- access.redhat.com/errata/RHSA-2019:1517nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2019:2145nvdThird Party Advisory
News mentions
0No linked articles in our index yet.