Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Mageia 2019-0080 Critical Security Advisory for gvfs Access Control

mageia
Calendar Grey February 14, 2019
Dist Mageia Esm H88
MGASA-2019-0080 - Updated gvfs packages fix security vulnerability Publication date: 14 Feb 2019 URL
The backend currently allows to access and modify files without prompting for password if any polkit authentication agent isn't available

Summary

The backend currently allows to access and modify files without prompting for password if any polkit authentication agent isn't available. This affects only users which belong to wheel group (i.e. those who are already allowed to use sudo). It doesn't allow privilege escalation for users, who don't belong to that group (CVE-2019-3827).

References

- https://bugs.mageia.org/show_bug.cgi?id=24215

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/Y43CRGATQPYWH2UXO6ZS7PYPCSZGTGED/

- https://ubuntu.com/security/notices/USN-3888-1

- https://www.cve.org/CVERecord?id=CVE-2019-3827

Resolution

SRPMS

- 6/core/gvfs-1.32.1-1.1.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 14 Feb 2019
URL: https://advisories.mageia.org/MGASA-2019-0080.html
Type: security
CVE: CVE-2019-3827

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here