CVE-2019-3827
An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.36%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious programs running under privileges of users belonging to the wheel group to further escalate its privileges by modifying system files without user's knowledge. Successful exploitation requires uncommon system configuration.
- CVSS 3.1
- 7.0 HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- gnome/gvfs
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2019:1517Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2145Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3827Issue Tracking, Patch, Third Party Advisory
- https://gitlab.gnome.org/GNOME/gvfs/merge_requests/31Patch, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:1517Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2145Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3827Issue Tracking, Patch, Third Party Advisory
- https://gitlab.gnome.org/GNOME/gvfs/merge_requests/31Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.