The backend currently allows to access and modify files without prompting for password if any polkit authentication agent isn't available. This affects only users which belong to wheel group (i.e. those who are already allowed to use sudo). It doesn't allow privilege escalation for users, who don't belong to that group (CVE-2019-3827). . MGASA-2019-0080 - Updated gvfs packages fix security vulnerability Publication date: 14 Feb 2019 URL: https://advisories.mageia.org/MGASA-2019-0080.html Type: security Affected Mageia releases: 6 CVE: CVE-2019-3827 The backend currently allows to access and modify files without prompting for password if any polkit authentication agent isn't available. This affects only users which belong to wheel group (i.e. those who are already allowed to use sudo). It doesn't allow privilege escalation for users, who don't belong to that group (CVE-2019-3827). References: - https://bugs.mageia.org/show_bug.cgi?id=24215 - https://lists.fedoraproject.org/archives/list/
Get the latest Linux and open source security news straight to your inbox.