UBUNTU-CVE-2019-12795
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-12795
UBUNTU-CVE-2019-12795
Summary:
Details: daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this server socket and issue D-Bus method calls. (Note that the server socket only accepts a single connection, so the attacker would have to discover the server and connect to the socket before its owner does.)
References: https://ubuntu.com/security/CVE-2019-12795, https://ubuntu.com/security/notices/USN-4053-1, https://www.cve.org/CVERecord?id=CVE-2019-12795
Affected packages
Package
Name: gvfs
Purl: pkg:deb/ubuntu/[email protected]~16.04.3?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
