Input validation error in gnome-desktop - CVE-2019-11460

 

Input validation error in gnome-desktop - CVE-2019-11460

Published: September 2, 2019


Vulnerability identifier: #VU20504
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11460
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper filtering of the TIOCSTI ioctl on 64-bit systems. A remote attacker can compromise the thumbnailer and escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push characters into the input buffer of the thumbnailer's controlling terminal.




Affected software

gnome-desktop
Gentoo Linux
Opensuse
openSUSE Leap
Fedora
libgnome-desktop-3-12
libgnome-desktop-3-12-debuginfo
libgnome-desktop-3-12-32bit
libgnome-desktop-3-12-32bit-debuginfo
gnome-desktop3

How to mitigate CVE-2019-11460

Install updates from vendor's website.

gnome-desktop - addressed in versions 3.30.2.2, 3.32.1.1
libgnome-desktop-3-12 - update to 3.26.2-150000.4.3.1
libgnome-desktop-3-12-debuginfo - update to 3.26.2-150000.4.3.1
libgnome-desktop-3-12-32bit - update to 3.26.2-150000.4.3.1
libgnome-desktop-3-12-32bit-debuginfo - update to 3.26.2-150000.4.3.1
gnome-desktop3 - update to 3.30.2.3-1.fc29

External References

Related Security Bulletins