Permissions, Privileges, and Access Controls in Gnome GLib - CVE-2019-12450
Published: June 3, 2019
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the application applies default directory permissions to files while copying them in file_copy_fallback() function in gio/gfile.c. A local user can interfere with the copying operation and gain access to otherwise restricted files, as the application applies correct access permissions after the file was copied only.
Such application behavior allows a local user to access potentially sensitive data or modify file contents in case directory permissions that were applied to the file allow such operations.
Affected software
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
glib2.0 (Ubuntu package)
glib (Alpine package)
glib2 (Red Hat package)
ibus (Red Hat package)
glib2
glib2-devel
glib2-fam
glib2-tests
Data Computing Appliance (DCA)
Ansible Automation Platform
Red Hat OpenShift Container Platform
How to mitigate CVE-2019-12450
glib (Alpine package) - addressed in versions 2.54.2-r1, 2.56.1-r1
glib2 (Red Hat package) - update to 2.56.1-7.el7
Data Computing Appliance (DCA) - addressed in versions Firmware tool 3H00, 4.2.1.0
Ansible Automation Platform - addressed in versions 1.0, 1.1
ibus (Red Hat package) - update to 1.5.17-11.el7
glib2 - update to 2.36.3-5.23
glib2 - update to 2.56.4-10
glib2-devel - update to 2.56.4-10
glib2-fam - update to 2.56.4-10
glib2-tests - update to 2.56.4-10
glib2 - update to 2.60.4-1.fc30
Red Hat OpenShift Container Platform - update to 4.3.40
External References
Related Security Bulletins
- Privilege escalation in GNOME Glib library
- Ubuntu update for GLib
- Ubuntu update for GLib
- OpenSUSE Linux update for glib2
- Amazon Linux AMI update for glib2
- Red Hat update for glib2
- Permissions, Privileges, and Access Controls in glib (Alpine package)
- Red Hat Enterprise Linux 7 update for glib2 and ibus
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Amazon Linux AMI update for glib2
- Anolis OS update for glib2 (Anolis OS 8.4)
- Multiple vulnerabilities in Ansible Automation Platform 1.0 packages
- Multiple vulnerabilities in Ansible Automation Platform 1.1 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.3
- Fedora 30 update for glib2