Description
daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this server socket and issue D-Bus method calls. (Note that the server socket only accepts a single connection, so the attacker would have to discover the server and connect to the socket before its owner does.)
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1827-1 | gvfs security update |
EUVD |
EUVD-2019-4378 | daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this server socket and issue D-Bus method calls. (Note that the server socket only accepts a single connection, so the attacker would have to discover the server and connect to the socket before its owner does.) |
Ubuntu USN |
USN-4053-1 | GVfs vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T23:32:54.828Z
Reserved: 2019-06-11T00:00:00.000Z
Link: CVE-2019-12795
No data.
Status : Modified
Published: 2019-06-11T22:29:06.560
Modified: 2024-11-21T04:23:35.817
Link: CVE-2019-12795
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN