ALPINE-CVE-2019-12450 PUBLISHED CVSS 9.800000190734863 CRITICAL

file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used.

Risk Scores

CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alpine:v3.16glib2.50.3-r0, 2.52.0-r0, 2.52.1-r0
Alpine:v3.13glib2.56.1-r0, 0, 2.58.1-r3
Alpine:v3.12glib2.58.1-r3, 2.18.3-r0, 0
Alpine:v3.8glib2.48.2-r0, 2.50.0-r0, 2.50.2-r0
Alpine:v3.15glib0, 2.26.0-r2, 2.27.92-r0
Alpine:v3.11glib2.46.2-r0, 0, 2.18.3-r0
Alpine:v3.20glib2.27.92-r0, 2.27.93-r0, 2.28.0-r0
Alpine:v3.17glib2.26.0-r2, 2.58.1-r3, 2.58.1-r2
Alpine:v3.18glib2.30.0-r0, 0, 2.18.3-r0
Alpine:v3.22glib2.20.4-r2, 2.58.1-r3, 2.58.1-r2
Alpine:v3.7glib2.20.3-r0, 2.18.3-r0, 2.18.4-r0
Alpine:v3.9glib2.52.0-r0, 2.20.4-r2, 2.20.5-r0
Alpine:v3.14glib2.24.0-r0, 2.48.1-r1, 2.48.1-r0
Alpine:v3.23glib2.32.4-r0, 2.58.1-r3, 2.58.1-r2
Alpine:v3.21glib2.26.0-r0, 0, 2.18.3-r0
Alpine:v3.19glib2.24.0-r4, 0, 2.18.3-r0
Alpine:v3.10glib2.24.2-r1, 2.27.92-r0, 2.27.93-r0

Timeline

References

Open in Interactive Console →