Input validation error in Nautilus - CVE-2019-11461

 

Input validation error in Nautilus - CVE-2019-11461

Published: September 2, 2019


Vulnerability identifier: #VU20506
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11461
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper filtering of the TIOCSTI ioctl on 64-bit systems. A local authenticated attacker can compromise the thumbnailer and escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push characters into the input buffer of the thumbnailer's controlling terminal.


Affected software

Nautilus
Gentoo Linux
Arch Linux
Opensuse
nautilus (Alpine package)

How to mitigate CVE-2019-11461

Install updates from vendor's website.

Nautilus - addressed in versions 3.30.6, 3.32.1
nautilus (Alpine package) - addressed in versions 3.32.1-r0, 3.32.3-r0

External References

Related Security Bulletins