SB2019072234 - Permissions, Privileges, and Access Controls in gvfs (Alpine package)
Published: July 22, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2019-12795)
The vulnerability allows a local attacker to escalate privileges on the system.
The vulnerability exists due to the daemon/gvfsdaemon.c opened a private D-Bus server socket without configuring an authorization rule. A local attacker can connect to this server socket and issue D-Bus method calls.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=0c012f09fb2eecc434fec5eab8c7ca78095c950a
- https://git.alpinelinux.org/aports/commit/?id=948e97dea02e32af012be430d5f87345a6263d46
- https://git.alpinelinux.org/aports/commit/?id=fe8e3f960f8c6ccd7df3b8175b21a261be8fc006
- https://git.alpinelinux.org/aports/commit/?id=5c7126a9f9c0fa81ccbcb651ea056d1c02540fbe
- https://git.alpinelinux.org/aports/commit/?id=60a89bb75d82e71f7b44cc05bf8f024f66ddfd23