Opened 6 years ago
Closed 6 years ago
#12214 closed enhancement (fixed)
Create patch to fix upstream gvfs issues
Reported by: | Douglas R. Reno | Owned by: | Douglas R. Reno |
---|---|---|---|
Priority: | highest | Milestone: | 9.0 |
Component: | BOOK | Version: | SVN |
Severity: | normal | Keywords: | |
Cc: |
Description ¶
As a result of the security update for Glib earlier this month, another set of security issues was found in gvfs. These allow for permission/access control bypass and file modification while transfer operations are in place.
I'm going to gen a patch with all of the commits except for translation updates since the release of gvfs-1.40.1.
Change History (3)
comment:1 by , 6 years ago
Owner: | changed from | to
---|---|
Status: | new → assigned |
comment:2 by , 6 years ago
Priority: | normal → highest |
---|
Note:
See TracTickets
for help on using tickets.
CVE-2019-12795
https://nvd.nist.gov/vuln/detail/CVE-2019-12795
7.8 HIGH
CVE-2019-12447
9.8 CRITICAL
https://nvd.nist.gov/vuln/detail/CVE-2019-12447
CVE-2019-12448
8.1 HIGH
https://nvd.nist.gov/vuln/detail/CVE-2019-12448/
CVE-2019-12449
9.8 CRITICAL
https://nvd.nist.gov/vuln/detail/CVE-2019-12449/