An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c has race conditions because the admin backend doesn't implement query_info_on_read/write. Reference: https://gitlab.gnome.org/GNOME/gvfs/commit/5cd76d627f4d1982b6e77a0e271ef9301732d09e
Created gvfs tracking bugs for this issue: Affects: fedora-all [bug 1728566]
Reference: https://www.openwall.com/lists/oss-security/2019/07/09/3
The race condition allows an attacker to copy/move a secret file abusing the fact that query_info_on_read/write methods are not implemented in the admin backend. The attacker can get read/write access to a copied file through this flaw.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:1766 https://access.redhat.com/errata/RHSA-2020:1766
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-12448