Wind River Support Network

HomeDefectsLIN10-5646
Fixed

LIN10-5646 : Security Advisory - gvfs - CVE-2019-3827

Created: Mar 28, 2019    Updated: May 18, 2019
Resolved Date: Apr 17, 2019
Found In Version: 10.17.41.15
Fix Version: 10.17.41.16
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious programs running under privileges of users belonging to the wheel group to further escalate its privileges by modifying system files without user's knowledge. Successful exploitation requires uncommon system configuration.

CREATE(Triage): {Link=https://nvd.nist.gov/vuln/detail/CVE-2019-3827 User=admin}

CVEs


Live chat
Online