file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used.
During installation, installed file permissions are set to allow anyone to modify those files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Glib | Gnome | 2.15.0 (including) | 2.61.1 (including) |
Red Hat Enterprise Linux 7 | RedHat | glib2-0:2.56.1-7.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | ibus-0:1.5.17-11.el7 | * |
Red Hat Enterprise Linux 8 | RedHat | glib2-0:2.56.4-7.el8 | * |
Red Hat OpenShift Do | RedHat | openshiftdo/odo-init-image-rhel7:1.1.3-2 | * |
Glib2.0 | Ubuntu | bionic | * |
Glib2.0 | Ubuntu | cosmic | * |
Glib2.0 | Ubuntu | devel | * |
Glib2.0 | Ubuntu | disco | * |
Glib2.0 | Ubuntu | trusty | * |
Glib2.0 | Ubuntu | trusty/esm | * |
Glib2.0 | Ubuntu | xenial | * |