daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this server socket and issue D-Bus method calls. (Note that the server socket only accepts a single connection, so the attacker would have to discover the server and connect to the socket before its owner does.)
During installation, installed file permissions are set to allow anyone to modify those files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gvfs | Gnome | * | 1.38.3 (excluding) |
Gvfs | Gnome | 1.40.0 (including) | 1.40.2 (excluding) |
Gvfs | Gnome | 1.41.0 (including) | 1.41.3 (excluding) |
Red Hat Enterprise Linux 8 | RedHat | accountsservice-0:0.6.50-7.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | appstream-data-0:8-20190805.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | baobab-0:3.28.0-2.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | chrome-gnome-shell-0:10.1-6.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | evince-0:3.28.4-3.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | file-roller-0:3.28.1-2.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gdk-pixbuf2-0:2.36.12-5.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gdm-1:3.28.3-22.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gjs-0:1.56.2-3.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gnome-control-center-0:3.28.2-5.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gnome-desktop3-0:3.32.2-1.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gnome-remote-desktop-0:0.1.6-5.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gnome-settings-daemon-0:3.32.0-4.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gnome-shell-0:3.32.2-9.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gnome-shell-extensions-0:3.32.1-10.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gnome-software-0:3.30.6-2.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gnome-tweaks-0:3.28.1-6.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gsettings-desktop-schemas-0:3.32.0-3.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gtk3-0:3.22.30-4.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gvfs-0:1.36.2-6.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | mozjs60-0:60.9.0-3.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | mutter-0:3.32.2-10.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | nautilus-0:3.28.1-10.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | pango-0:1.42.4-6.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | pidgin-0:2.13.0-5.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | plymouth-0:0.9.3-15.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | SDL-0:1.2.15-35.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | wayland-protocols-0:1.17-1.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | webkit2gtk3-0:2.24.3-1.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | accountsservice-0:0.6.50-7.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | appstream-data-0:8-20190805.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | baobab-0:3.28.0-2.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | chrome-gnome-shell-0:10.1-6.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | evince-0:3.28.4-3.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | file-roller-0:3.28.1-2.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gdk-pixbuf2-0:2.36.12-5.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gdm-1:3.28.3-22.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gjs-0:1.56.2-3.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gnome-control-center-0:3.28.2-5.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gnome-desktop3-0:3.32.2-1.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gnome-remote-desktop-0:0.1.6-5.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gnome-settings-daemon-0:3.32.0-4.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gnome-shell-0:3.32.2-9.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gnome-shell-extensions-0:3.32.1-10.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gnome-software-0:3.30.6-2.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gnome-tweaks-0:3.28.1-6.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gsettings-desktop-schemas-0:3.32.0-3.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gtk3-0:3.22.30-4.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gvfs-0:1.36.2-6.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | mozjs60-0:60.9.0-3.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | mutter-0:3.32.2-10.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | nautilus-0:3.28.1-10.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | pango-0:1.42.4-6.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | pidgin-0:2.13.0-5.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | plymouth-0:0.9.3-15.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | SDL-0:1.2.15-35.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | wayland-protocols-0:1.17-1.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | webkit2gtk3-0:2.24.3-1.el8 | * |
Gvfs | Ubuntu | bionic | * |
Gvfs | Ubuntu | cosmic | * |
Gvfs | Ubuntu | devel | * |
Gvfs | Ubuntu | disco | * |
Gvfs | Ubuntu | trusty | * |
Gvfs | Ubuntu | upstream | * |
Gvfs | Ubuntu | xenial | * |