MGASA-2019-0080 - Updated gvfs packages fix security vulnerability

Publication date: 14 Feb 2019
URL: https://advisories.mageia.org/MGASA-2019-0080.html
Type: security
Affected Mageia releases: 6
CVE: CVE-2019-3827

The backend currently allows to access and modify files without prompting
for password if any polkit authentication agent isn't available. This
affects only users which belong to wheel group (i.e. those who are already
allowed to use sudo). It doesn't allow privilege escalation for users, who
don't belong to that group (CVE-2019-3827).

References:
- https://bugs.mageia.org/show_bug.cgi?id=24215
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/Y43CRGATQPYWH2UXO6ZS7PYPCSZGTGED/
- https://ubuntu.com/security/notices/USN-3888-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3827

SRPMS:
- 6/core/gvfs-1.32.1-1.1.mga6

Mageia 2019-0080: gvfs security update

The backend currently allows to access and modify files without prompting for password if any polkit authentication agent isn't available

Summary

The backend currently allows to access and modify files without prompting for password if any polkit authentication agent isn't available. This affects only users which belong to wheel group (i.e. those who are already allowed to use sudo). It doesn't allow privilege escalation for users, who don't belong to that group (CVE-2019-3827).

References

- https://bugs.mageia.org/show_bug.cgi?id=24215

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/Y43CRGATQPYWH2UXO6ZS7PYPCSZGTGED/

- https://ubuntu.com/security/notices/USN-3888-1

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3827

Resolution

MGASA-2019-0080 - Updated gvfs packages fix security vulnerability

SRPMS

- 6/core/gvfs-1.32.1-1.1.mga6

Severity
Publication date: 14 Feb 2019
URL: https://advisories.mageia.org/MGASA-2019-0080.html
Type: security
CVE: CVE-2019-3827

Related News