Bug 1728564 (CVE-2019-12448) - CVE-2019-12448 gvfs: race condition in daemon/gvfsbackendadmin.c due to admin backend not implementing query_info_on_read/write
Summary: CVE-2019-12448 gvfs: race condition in daemon/gvfsbackendadmin.c due to admin...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2019-12448
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1728566 1754505 1754506 1754507
Blocks: 1728569
TreeView+ depends on / blocked
 
Reported: 2019-07-10 07:22 UTC by Dhananjay Arunesh
Modified: 2020-04-28 16:33 UTC (History)
2 users (show)

Fixed In Version: gvfs 1.41.3
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2020-04-28 16:33:17 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2020:1766 0 None None None 2020-04-28 15:51:00 UTC

Description Dhananjay Arunesh 2019-07-10 07:22:14 UTC
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c has race conditions because the admin backend doesn't implement query_info_on_read/write.

Reference:
https://gitlab.gnome.org/GNOME/gvfs/commit/5cd76d627f4d1982b6e77a0e271ef9301732d09e

Comment 1 Dhananjay Arunesh 2019-07-10 07:22:29 UTC
Created gvfs tracking bugs for this issue:

Affects: fedora-all [bug 1728566]

Comment 2 Riccardo Schirone 2019-09-20 11:44:13 UTC
Reference:
https://www.openwall.com/lists/oss-security/2019/07/09/3

Comment 5 Riccardo Schirone 2019-09-23 12:46:07 UTC
The race condition allows an attacker to copy/move a secret file abusing the fact that query_info_on_read/write methods are not implemented in the admin backend. The attacker can get read/write access to a copied file through this flaw.

Comment 7 errata-xmlrpc 2020-04-28 15:50:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2020:1766 https://access.redhat.com/errata/RHSA-2020:1766

Comment 8 Product Security DevOps Team 2020-04-28 16:33:17 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2019-12448


Note You need to log in before you can comment on or make changes to this bug.