Bug 1716284 (CVE-2019-11460) - CVE-2019-11460 gnome-desktop: thumbnailer security bypass
Summary: CVE-2019-11460 gnome-desktop: thumbnailer security bypass
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2019-11460
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1716290 1716291 1716292 1718719 1718720
Blocks: 1716288
TreeView+ depends on / blocked
 
Reported: 2019-06-03 07:16 UTC by Dhananjay Arunesh
Modified: 2021-10-27 03:29 UTC (History)
10 users (show)

Fixed In Version: gnome-desktop 3.30.2.2, gnome-deskop 3.32.1.1
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-10-27 03:29:02 UTC
Embargoed:


Attachments (Terms of Use)

Description Dhananjay Arunesh 2019-06-03 07:16:19 UTC
An issue was discovered in GNOME gnome-desktop 3.26, 3.28, and 3.30 prior to 3.30.2.2, and 3.32 prior to 3.32.1.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push characters into the input buffer of the thumbnailer's controlling terminal, allowing an attacker to escape the sandbox if the thumbnailer has a controlling terminal. This is due to improper filtering of the TIOCSTI ioctl on 64-bit systems, similar to CVE-2019-10063.

Reference:
https://gitlab.gnome.org/GNOME/gnome-desktop/issues/112

Comment 1 Dhananjay Arunesh 2019-06-03 07:24:28 UTC
Created gnome-desktop tracking bugs for this issue:

Affects: fedora-all [bug 1716290]


Created gnome-desktop3 tracking bugs for this issue:

Affects: fedora-all [bug 1716291]

Comment 2 Dhananjay Arunesh 2019-06-03 07:24:48 UTC
Created gnome-desktop tracking bugs for this issue:

Affects: epel-7 [bug 1716292]

Comment 4 Huzaifa S. Sidhpurwala 2019-06-10 04:20:07 UTC
Upstream patch: https://gitlab.gnome.org/GNOME/nautilus/commit/2ddba428ef2b13d0620bd599c3635b9c11044659


Note You need to log in before you can comment on or make changes to this bug.