CVE-2019-12795
gvfs: improper authorization in daemon/gvfsdaemon.c in gvfsd
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this server socket and issue D-Bus method calls. (Note that the server socket only accepts a single connection, so the attacker would have to discover the server and connect to the socket before its owner does.)
daemon/gvfsdaemon.c in gvfsd from GNOME gvfs anterior 1.38.3, 1.40.x anterior 1.40.2, y 1.41.x anterior 1.41.3 abrió un socket de servidor en D-Bus privado, sin configurar una regla de autorización. Un atacante local podría conectarse a esta toma de servidor y generar llamadas de tipo D-Bus. (tener en cuenta que la toma de servidor solo acepta una única conexione, así el atacante podría tener que descubrir el servidor y conectarse al socket antes que su propio propietario lo haga.
"
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-06-11 CVE Reserved
- 2019-06-11 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-276: Incorrect Default Permissions
- CWE-285: Improper Authorization
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/108741 | Vdb Entry | |
https://lists.debian.org/debian-lts-announce/2019/06/msg00014.html | Mailing List |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gnome Search vendor "Gnome" | Gvfs Search vendor "Gnome" for product "Gvfs" | < 1.38.3 Search vendor "Gnome" for product "Gvfs" and version " < 1.38.3" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Gvfs Search vendor "Gnome" for product "Gvfs" | >= 1.40.0 < 1.40.2 Search vendor "Gnome" for product "Gvfs" and version " >= 1.40.0 < 1.40.2" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Gvfs Search vendor "Gnome" for product "Gvfs" | >= 1.41.0 < 1.41.3 Search vendor "Gnome" for product "Gvfs" and version " >= 1.41.0 < 1.41.3" | - |
Affected
|