CVE-2019-12795

CVE Details

Release Date:2019-06-11

Description


daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this server socket and issue D-Bus method calls. (Note that the server socket only accepts a single connection, so the attacker would have to discover the server and connect to the socket before its owner does.)

See more information about CVE-2019-12795 from MITRE CVE dictionary and NIST NVD


CVSS v3.0 metrics


NOTE: The following CVSS v3.0 metrics and score provided are preliminary and subject to review.

Base Score: 7.8 Base Metrics: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Access Vector: Local network Attack Complexity: Low
Privileges Required: Low User Interaction: None
Scope: Unchanged Confidentiality Impact: High
Integrity Impact: High Availability Impact: High

Errata information


PlatformErrataRelease Date
Oracle Linux version 8 (SDL)ELSA-2019-35532019-11-14
Oracle Linux version 8 (accountsservice)ELSA-2019-35532019-11-14
Oracle Linux version 8 (appstream-data)ELSA-2019-35532019-11-14
Oracle Linux version 8 (baobab)ELSA-2019-35532019-11-14
Oracle Linux version 8 (chrome-gnome-shell)ELSA-2019-35532019-11-14
Oracle Linux version 8 (evince)ELSA-2019-35532019-11-14
Oracle Linux version 8 (file-roller)ELSA-2019-35532019-11-14
Oracle Linux version 8 (gdk-pixbuf2)ELSA-2019-35532019-11-14
Oracle Linux version 8 (gdm)ELSA-2019-35532019-11-14
Oracle Linux version 8 (gjs)ELSA-2019-35532019-11-14
Oracle Linux version 8 (gnome-control-center)ELSA-2019-35532019-11-14
Oracle Linux version 8 (gnome-desktop3)ELSA-2019-35532019-11-14
Oracle Linux version 8 (gnome-remote-desktop)ELSA-2019-35532019-11-14
Oracle Linux version 8 (gnome-settings-daemon)ELSA-2019-35532019-11-14
Oracle Linux version 8 (gnome-shell)ELSA-2019-35532019-11-14
Oracle Linux version 8 (gnome-shell-extensions)ELSA-2019-35532019-11-14
Oracle Linux version 8 (gnome-software)ELSA-2019-35532019-11-14
Oracle Linux version 8 (gnome-tweaks)ELSA-2019-35532019-11-14
Oracle Linux version 8 (gsettings-desktop-schemas)ELSA-2019-35532019-11-14
Oracle Linux version 8 (gtk3)ELSA-2019-35532019-11-14
Oracle Linux version 8 (gvfs)ELSA-2019-35532019-11-14
Oracle Linux version 8 (mozjs60)ELSA-2019-35532019-11-14
Oracle Linux version 8 (mutter)ELSA-2019-35532019-11-14
Oracle Linux version 8 (nautilus)ELSA-2019-35532019-11-14
Oracle Linux version 8 (pango)ELSA-2019-35532019-11-14
Oracle Linux version 8 (pidgin)ELSA-2019-35532019-11-14
Oracle Linux version 8 (plymouth)ELSA-2019-35532019-11-14
Oracle Linux version 8 (wayland-protocols)ELSA-2019-35532019-11-14
Oracle Linux version 8 (webkit2gtk3)ELSA-2019-35532019-11-14



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete