VDB
GCVE-VVD-MAGEIA-2019-214
GCVE-VVD-MAGEIA-2019-214
Advisory Published
Updated gvfs package fixes security vulnerabilities:
* daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid
is not used (CVE-2019-12447).
* daemon/gvfsbackendadmin.c has race conditions because the admin backend
doesn't implement query_info_on_read/write (CVE-2019-12448).
* daemon/gvfsbackendadmin.c mishandles a file's user and group ownership
during move (and copy with G_FILE_COPY_ALL_METADATA) operations from
admin:// to file:// URIs, because root privileges are unavailable
(CVE-2019-12449).
* daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x
before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server
socket without configuring an authorization rule (CVE-2019-12795)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | mgaonline | 0 (affected), 3.24.2-1.mga6 (unaffected) | — |
| Mageia | gvfs | 0 (affected), 1.32.1-1.2.mga6 (unaffected), 0 (affected), 1.32.1-1.2.mga6 (unaffected) | — |
| Mageia | gvfs | 0 (affected), 1.40.1-4.1.mga7 (unaffected), 0 (affected), 1.40.1-4.1.mga7 (unaffected) | — |
Aliases
Transitive aliases
BDU:2019-02517GSD-2019-12449EUVD-2019-4056RHSA-2019:3553GHSA-4hjh-mpfm-qhm5GSD-2019-12447EUVD-2019-13448CVE-2018-20337BDU:2019-02516GHSA-c9h6-p6mv-6rr7EUVD-2018-12895GHSA-whx7-c8j2-42vvBDU:2019-02514BDU:2019-02515GHSA-pfhm-wwqj-c296BDU:2020-02203VVD-GENTOO-2019-690144EUVD-2019-4058GSD-2019-12448CVE-2019-3825SUSE-SU-2024:2681-1GHSA-cvf3-3jj2-mv9fALSA-2020:1766BDU:2019-02106EUVD-2019-4378ALSA-2019:3553GHSA-x42r-3m27-mhv7EUVD-2019-4057VVD-GENTOO-2019-679474GSD-2019-12795
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.