Opened 7 years ago
Closed 7 years ago
#12214 closed enhancement (fixed)
Create patch to fix upstream gvfs issues
| Reported by: | Douglas R. Reno | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | highest | Milestone: | 9.0 |
| Component: | BOOK | Version: | SVN |
| Severity: | medium | Keywords: | |
| Cc: |
Description
As a result of the security update for Glib earlier this month, another set of security issues was found in gvfs. These allow for permission/access control bypass and file modification while transfer operations are in place.
I'm going to gen a patch with all of the commits except for translation updates since the release of gvfs-1.40.1.
Change History (3)
comment:1 by , 7 years ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 7 years ago
| Priority: | normal → highest |
|---|
Note:
See TracTickets
for help on using tickets.

CVE-2019-12795
https://nvd.nist.gov/vuln/detail/CVE-2019-12795
7.8 HIGH
CVE-2019-12447
9.8 CRITICAL
https://nvd.nist.gov/vuln/detail/CVE-2019-12447
CVE-2019-12448
8.1 HIGH
https://nvd.nist.gov/vuln/detail/CVE-2019-12448/
CVE-2019-12449
9.8 CRITICAL
https://nvd.nist.gov/vuln/detail/CVE-2019-12449/