CVE-2019-13012
published 2019-06-28CVE-2019-13012: The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir, NULL, NULL) and…
PriorityP342high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
3.21%
86.7th percentile
The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir, NULL, NULL) and files using g_file_replace_contents (kfsb->file, contents, length, NULL, FALSE, G_FILE_CREATE_REPLACE_DESTINATION, NULL, NULL, NULL). Consequently, it does not properly restrict directory (and file) permissions. Instead, for directories, 0777 permissions are used; for files, default file permissions are used. This is similar to CVE-2019-12450.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glib2.0 | < glib2.0 2.60.5-1 (bookworm) | glib2.0 2.60.5-1 (bookworm) |
| gnome | glib | >= 2.0.0 < 2.59.1 | 2.59.1 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_glib_2.58.0-6_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GLib vulnerability
vendor_ubuntu·2019-07-08
CVE-2019-13012 GLib vulnerability
Title: GLib vulnerability
Summary: GLib did not properly restrict directory and file permissions.
USN-4049-1 fixed a vulnerability in GLib. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that GLib created directories and files without properly
restricting permissions. An attacker could possibly use this issue to access
sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
GLib vulnerability
vendor_ubuntu·2019-07-08
CVE-2019-13012 GLib vulnerability
Title: GLib vulnerability
Summary: GLib did not properly restrict directory and file permissions.
It was discovered that GLib created directories and files without properly
restricting permissions. An attacker could possibly use this issue to access
sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
glib2: insecure permissions for files and directories
vendor_redhat·2019-06-28·CVSS 9.8
CVE-2019-13012 [CRITICAL] CWE-732 glib2: insecure permissions for files and directories
glib2: insecure permissions for files and directories
The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir, NULL, NULL) and files using g_file_replace_contents (kfsb->file, contents, length, NULL, FALSE, G_FILE_CREATE_REPLACE_DESTINATION, NULL, NULL, NULL). Consequently, it does not properly restrict directory (and file) permissions. Instead, for directories, 0777 permissions are used; for files, default file permissions are used. This is similar to CVE-2019-12450.
Statement: This issue affects glib2 as shipped with Red Hat Enterprise Linux 6, 7 and 8 and was rated as having a Low security impact by Red Hat Product Security team.
Although Red Hat Enterprise Linux versions above ships the vulnerable
Microsoft
The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir NULL NULL) and files using g_file_replace_contents (kfsb-
vendor_msrc·2019-06-11·CVSS 7.5
CVE-2019-13012 [CRITICAL] CWE-732 The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir NULL NULL) and files using g_file_replace_contents (kfsb-
The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir NULL NULL) and files using g_file_replace_contents (kfsb->file contents length NULL FALSE G_FILE_CREATE_REPLACE_DESTINATION NULL NULL NULL). Consequently it does not properly restrict directory (and file) permissions. Instead for directories 0777 permissions are used; for files default file permissions are used. This is similar to CVE-2019-12450.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure
Debian
CVE-2019-13012: glib2.0 - The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates d...
vendor_debian·2019·CVSS 9.8
CVE-2019-13012 [CRITICAL] CVE-2019-13012: glib2.0 - The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates d...
The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir, NULL, NULL) and files using g_file_replace_contents (kfsb->file, contents, length, NULL, FALSE, G_FILE_CREATE_REPLACE_DESTINATION, NULL, NULL, NULL). Consequently, it does not properly restrict directory (and file) permissions. Instead, for directories, 0777 permissions are used; for files, default file permissions are used. This is similar to CVE-2019-12450.
Scope: local
bookworm: resolved (fixed in 2.60.5-1)
bullseye: resolved (fixed in 2.60.5-1)
forky: resolved (fixed in 2.60.5-1)
sid: resolved (fixed in 2.60.5-1)
trixie: resolved (fixed in 2.60.5-1)
GHSA
GHSA-4cmr-h54h-4w78: The keyfile settings backend in GNOME GLib (aka glib2
ghsa_unreviewed·2022-05-24·CVSS 9.8
CVE-2019-13012 [CRITICAL] CWE-732 GHSA-4cmr-h54h-4w78: The keyfile settings backend in GNOME GLib (aka glib2
The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.59.1 creates directories using g_file_make_directory_with_parents (kfsb->dir, NULL, NULL) and files using g_file_replace_contents (kfsb->file, contents, length, NULL, FALSE, G_FILE_CREATE_REPLACE_DESTINATION, NULL, NULL, NULL). Consequently, it does not properly restrict directory (and file) permissions. Instead, for directories, 0777 permissions are used; for files, default file permissions are used. This is similar to CVE-2019-12450.
OSV
CVE-2019-13012: The keyfile settings backend in GNOME GLib (aka glib2
osv·2019-06-28·CVSS 9.8
CVE-2019-13012 [CRITICAL] CVE-2019-13012: The keyfile settings backend in GNOME GLib (aka glib2
The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir, NULL, NULL) and files using g_file_replace_contents (kfsb->file, contents, length, NULL, FALSE, G_FILE_CREATE_REPLACE_DESTINATION, NULL, NULL, NULL). Consequently, it does not properly restrict directory (and file) permissions. Instead, for directories, 0777 permissions are used; for files, default file permissions are used. This is similar to CVE-2019-12450.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-13012 glib2: insecure permissions for files and directories
bugzilla·2019-07-10·CVSS 9.8
CVE-2019-13012 [CRITICAL] CVE-2019-13012 glib2: insecure permissions for files and directories
CVE-2019-13012 glib2: insecure permissions for files and directories
The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.59.1 creates
directories using g_file_make_directory_with_parents (kfsb->dir, NULL, NULL) and
files using g_file_replace_contents (kfsb->file, contents, length, NULL, FALSE,
G_FILE_CREATE_REPLACE_DESTINATION, NULL, NULL, NULL). Consequently, it does not
properly restrict directory (and file) permissions. Instead, for directories,
0777 permissions are used; for files, default file permissions are used. This is
similar to CVE-2019-12450.
Reference:
https://gitlab.gnome.org/GNOME/glib/issues/1658
Upstream commit:
https://gitlab.gnome.org/GNOME/glib/commit/5e4da714f00f6bfb2ccd6d73d61329c6f3a08429
Discussion:
Created glib2 tracking bugs for this issue:
Aff
Bugzilla
CVE-2019-13012 glib2: insecure permissions for files and directories [fedora-all]
bugzilla·2019-07-10·CVSS 7.5
CVE-2019-13012 [HIGH] CVE-2019-13012 glib2: insecure permissions for files and directories [fedora-all]
CVE-2019-13012 glib2: insecure permissions for files and directories [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00022.htmlhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=931234#12https://gitlab.gnome.org/GNOME/glib/commit/5e4da714f00f6bfb2ccd6d73d61329c6f3a08429https://gitlab.gnome.org/GNOME/glib/issues/1658https://gitlab.gnome.org/GNOME/glib/merge_requests/450https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2019/07/msg00029.htmlhttps://lists.debian.org/debian-lts-announce/2019/08/msg00004.htmlhttps://security.netapp.com/advisory/ntap-20190806-0003/https://usn.ubuntu.com/4049-1/https://usn.ubuntu.com/4049-2/http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00022.htmlhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=931234#12https://gitlab.gnome.org/GNOME/glib/commit/5e4da714f00f6bfb2ccd6d73d61329c6f3a08429https://gitlab.gnome.org/GNOME/glib/issues/1658https://gitlab.gnome.org/GNOME/glib/merge_requests/450https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2019/07/msg00029.htmlhttps://lists.debian.org/debian-lts-announce/2019/08/msg00004.htmlhttps://security.netapp.com/advisory/ntap-20190806-0003/https://usn.ubuntu.com/4049-1/https://usn.ubuntu.com/4049-2/
2019-06-28
Published