SB2019072232 - Race condition in gvfs (Alpine package)
Published: July 22, 2019
Security Bulletin ID
SB2019072232
Severity
High
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Race condition (CVE-ID: CVE-2019-12448)
The vulnerability allows a remote attacker to overwrite or access sensitive information, or cause a denial of service (DoS) condition on a targeted system.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=0c012f09fb2eecc434fec5eab8c7ca78095c950a
- https://git.alpinelinux.org/aports/commit/?id=948e97dea02e32af012be430d5f87345a6263d46
- https://git.alpinelinux.org/aports/commit/?id=fe8e3f960f8c6ccd7df3b8175b21a261be8fc006
- https://git.alpinelinux.org/aports/commit/?id=5c7126a9f9c0fa81ccbcb651ea056d1c02540fbe
- https://git.alpinelinux.org/aports/commit/?id=60a89bb75d82e71f7b44cc05bf8f024f66ddfd23