The updated packages fix a security vulnerability: file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used. (CVE-2019-12450) . MGASA-2019-0352 - Updated glib2.0 packages fix security vulnerability Publication date: 30 Nov 2019 URL: https://advisories.mageia.org/MGASA-2019-0352.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-12450 The updated packages fix a security vulnerability: file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used. (CVE-2019-12450) References: - https://bugs.mageia.org/show_bug.cgi?id=25276 - https://ubuntu.com/security/notices/USN-4014-1 - https://access.redhat.com/errata/RHSA-2019:3530 - - https://www.cve.org/CVERecord?id=CVE-2019-12450 SRPMS: - 7/core/glib2.0-2.60.2-1.2.mga7 . The latest Mageia glib2.0 updates resolve a significant file permissions vulnerability impacting secure activities. Discover further details here.. Mageia Security Update, glib2.0 Patch, File Permission Fix, Open Source Security. . Severity: Critical. LinuxSecurity.com Team
It was discovered that GLib does not properly restrict some file permissions while a copy operation is in progress; instead, default permissions are used. . Package : glib2.0 Version : 2.42.1-1+deb8u1 CVE ID : CVE-2019-12450 Debian Bug : 929753 It was discovered that GLib does not properly restrict some file permissions while a copy operation is in progress; instead, default permissions are used. For Debian 8 "Jessie", this problem has been fixed in version 2.42.1-1+deb8u1. We recommend that you upgrade your glib2.0 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . glib2.0 vulnerability patched regarding access control flaw in Debian system. Users advised to upgrade promptly.. glib2.0 Security Update, Debian Bug 929753, File Permissions Fix, CVE-2019-12450. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.