Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.844087
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-4053-1)
Summary:The remote host is missing an update for the 'gvfs' package(s) announced via the USN-4053-1 advisory.
Description:Summary:
The remote host is missing an update for the 'gvfs' package(s) announced via the USN-4053-1 advisory.

Vulnerability Insight:
It was discovered that GVfs incorrectly handled the admin backend. Files
created or moved by the admin backend could end up with the wrong ownership
information, contrary to expectations. This issue only affected Ubuntu
18.04 LTS, Ubuntu 18.10, and Ubuntu 19.04. (CVE-2019-12447, CVE-2019-12448,
CVE-2019-12449)

It was discovered that GVfs incorrectly handled authentication on its
private D-Bus socket. A local attacker could possibly connect to this
socket and issue D-Bus calls. (CVE-2019-12795)

Affected Software/OS:
'gvfs' package(s) on Ubuntu 16.04, Ubuntu 18.04, Ubuntu 18.10, Ubuntu 19.04.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2019-12447
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M2DQVOL5H5BVLXYCEB763DCIYJQ7ZUQ2/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FP6BFQUPQRVRRFIYHFWWB6RHJNEB4LGQ/
https://gitlab.gnome.org/GNOME/gvfs/commit/d7d362995aa0cb8905c8d5c2a2a4c305d2ffff80
http://www.openwall.com/lists/oss-security/2019/07/09/3
SuSE Security Announcement: openSUSE-SU-2019:1697 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00009.html
SuSE Security Announcement: openSUSE-SU-2019:1699 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00008.html
https://usn.ubuntu.com/4053-1/
Common Vulnerability Exposure (CVE) ID: CVE-2019-12448
https://gitlab.gnome.org/GNOME/gvfs/commit/764e9af7522e3096c0f44613c330377d31c9bbb5
Common Vulnerability Exposure (CVE) ID: CVE-2019-12449
https://gitlab.gnome.org/GNOME/gvfs/commit/409619412e11be146a31b9a99ed965925f1aabb8
Common Vulnerability Exposure (CVE) ID: CVE-2019-12795
BugTraq ID: 108741
http://www.securityfocus.com/bid/108741
https://gitlab.gnome.org/GNOME/gvfs/commit/70dbfc68a79faac49bd3423e079cb6902522082a
https://gitlab.gnome.org/GNOME/gvfs/commit/d8c9138bf240975848b1c54db648ec4cd516a48f
https://gitlab.gnome.org/GNOME/gvfs/commit/e3808a1b4042761055b1d975333a8243d67b8bfe
https://lists.debian.org/debian-lts-announce/2019/06/msg00014.html
RedHat Security Advisories: RHSA-2019:3553
https://access.redhat.com/errata/RHSA-2019:3553
CopyrightCopyright (C) 2019 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.