Permissions, Privileges, and Access Controls in Gnome GLib - CVE-2019-12450

 

Permissions, Privileges, and Access Controls in Gnome GLib - CVE-2019-12450

Published: June 3, 2019


Vulnerability identifier: #VU18658
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12450
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to the application applies default directory permissions to files while copying them in file_copy_fallback() function in gio/gfile.c. A local user can interfere with the copying operation and gain access to otherwise restricted files, as the application applies correct access permissions after the file was copied only.

Such application behavior allows a local user to access potentially sensitive data or modify file contents in case directory permissions that were applied to the file allow such operations.


Affected software

Gnome GLib
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
glib2.0 (Ubuntu package)
glib (Alpine package)
glib2 (Red Hat package)
ibus (Red Hat package)
glib2
glib2-devel
glib2-fam
glib2-tests
Data Computing Appliance (DCA)
Ansible Automation Platform
Red Hat OpenShift Container Platform

How to mitigate CVE-2019-12450

Install updates from vendor's website.

glib2.0 (Ubuntu package) - addressed in versions 2.32.4-0ubuntu1.2, 2.40.2-0ubuntu1.1+esm1, 2.48.2-0ubuntu4.2, 2.56.4-0ubuntu0.18.04.3, 2.58.1-2ubuntu0.1, 2.60.0-1ubuntu0.1
glib (Alpine package) - addressed in versions 2.54.2-r1, 2.56.1-r1
glib2 (Red Hat package) - update to 2.56.1-7.el7
Data Computing Appliance (DCA) - addressed in versions Firmware tool 3H00, 4.2.1.0
Ansible Automation Platform - addressed in versions 1.0, 1.1
ibus (Red Hat package) - update to 1.5.17-11.el7
glib2 - update to 2.36.3-5.23
glib2 - update to 2.56.4-10
glib2-devel - update to 2.56.4-10
glib2-fam - update to 2.56.4-10
glib2-tests - update to 2.56.4-10
glib2 - update to 2.60.4-1.fc30
Red Hat OpenShift Container Platform - update to 4.3.40

External References

Related Security Bulletins