Permissions, Privileges, and Access Controls in gvfs - CVE-2019-12447
Published: June 5, 2019 / Updated: June 13, 2019
gvfs
Detailed vulnerability description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to functionality in the daemon/gvfsbackendadmin.c file doesn't make use of "setfsuid" call when handling ownership permissions. A remote attacker can gain unauthorized access to arbitrary files on a system.