Wind River Support Network

HomeDefectsLIN1018-3792
Fixed

LIN1018-3792 : Security Advisory - gvfs - CVE-2019-3827

Created: Mar 28, 2019    Updated: Apr 24, 2019
Resolved Date: Apr 8, 2019
Found In Version: unknown
Fix Version: 10.18.44.6
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious programs running under privileges of users belonging to the wheel group to further escalate its privileges by modifying system files without user's knowledge. Successful exploitation requires uncommon system configuration.

CREATE(Triage): {Link=https://nvd.nist.gov/vuln/detail/CVE-2019-3827 User=admin}

CVEs


Live chat
Online