Release Date: | 2019-06-11 |
daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this server socket and issue D-Bus method calls. (Note that the server socket only accepts a single connection, so the attacker would have to discover the server and connect to the socket before its owner does.)
See more information about CVE-2019-12795 from MITRE CVE dictionary and NIST NVD
NOTE: The following CVSS v3.0 metrics and score provided are preliminary and subject to review.
Base Score: | 7.8 | Base Metrics: | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Access Vector: | Local network | Attack Complexity: | Low |
Privileges Required: | Low | User Interaction: | None |
Scope: | Unchanged | Confidentiality Impact: | High |
Integrity Impact: | High | Availability Impact: | High |
Platform | Errata | Release Date |
Oracle Linux version 8 (SDL) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (accountsservice) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (appstream-data) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (baobab) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (chrome-gnome-shell) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (evince) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (file-roller) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (gdk-pixbuf2) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (gdm) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (gjs) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (gnome-control-center) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (gnome-desktop3) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (gnome-remote-desktop) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (gnome-settings-daemon) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (gnome-shell) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (gnome-shell-extensions) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (gnome-software) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (gnome-tweaks) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (gsettings-desktop-schemas) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (gtk3) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (gvfs) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (mozjs60) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (mutter) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (nautilus) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (pango) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (pidgin) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (plymouth) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (wayland-protocols) | ELSA-2019-3553 | 2019-11-14 |
Oracle Linux version 8 (webkit2gtk3) | ELSA-2019-3553 | 2019-11-14 |
This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team