MGASA-2019-0080
Dashboard / Vulnerabilities / MGASA-2019-0080
Summary: Updated gvfs packages fix security vulnerability
Details: The backend currently allows to access and modify files without prompting for password if any polkit authentication agent isn't available. This affects only users which belong to wheel group (i.e. those who are already allowed to use sudo). It doesn't allow privilege escalation for users, who don't belong to that group (CVE-2019-3827).
References: https://advisories.mageia.org/MGASA-2019-0080.html, https://bugs.mageia.org/show_bug.cgi?id=24215, https://lists.fedoraproject.org/archives/list/[email protected]/thread/Y43CRGATQPYWH2UXO6ZS7PYPCSZGTGED/, https://usn.ubuntu.com/3888-1/
Affected packages
Package
Name: gvfs
Purl: pkg:rpm/mageia/gvfs?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
