The backend currently allows to access and modify files without prompting
for password if any polkit authentication agent isn't available. This
affects only users which belong to wheel group (i.e. those who are already
allowed to use sudo). It doesn't allow privilege escalation for users, who
don't belong to that group (CVE-2019-3827).
- https://bugs.mageia.org/show_bug.cgi?id=24215
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/Y43CRGATQPYWH2UXO6ZS7PYPCSZGTGED/
- https://ubuntu.com/security/notices/USN-3888-1
- https://www.cve.org/CVERecord?id=CVE-2019-3827
- 6/core/gvfs-1.32.1-1.1.mga6
Get the latest Linux and open source security news straight to your inbox.