CVE-2019-3827
published 2019-03-25CVE-2019-3827: An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users…
PriorityP335high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.37%
29.1th percentile
An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious programs running under privileges of users belonging to the wheel group to further escalate its privileges by modifying system files without user's knowledge. Successful exploitation requires uncommon system configuration.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gvfs | < gvfs 1.38.1-3 (bookworm) | gvfs 1.38.1-3 (bookworm) |
| gnome | gvfs | < 1.39.4 | 1.39.4 |
| gnome | gvfs | >= 0 < 1.38.1-3 | 1.38.1-3 |
| gnome | gvfs | >= 0 < 1.38.1-3 | 1.38.1-3 |
| gnome | gvfs | >= 0 < 1.38.1-3 | 1.38.1-3 |
| gnome | gvfs | >= 0 < 1.38.1-3 | 1.38.1-3 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:P/A:N
osv7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GVfs vulnerability
vendor_ubuntu·2019-02-12
CVE-2019-3827 GVfs vulnerability
Title: GVfs vulnerability
Summary: GVfs could be made to expose sensitive information if it received
a specially crafted input.
It was discovered that GVfs incorrectly handled certain inputs. An attacker
could possibly use this issue to access sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-3827: gvfs - An incorrect permission check in the admin backend in gvfs before version 1.39.4...
vendor_debian·2019·CVSS 7.0
CVE-2019-3827 [HIGH] CVE-2019-3827: gvfs - An incorrect permission check in the admin backend in gvfs before version 1.39.4...
An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious programs running under privileges of users belonging to the wheel group to further escalate its privileges by modifying system files without user's knowledge. Successful exploitation requires uncommon system configuration.
Scope: local
bookworm: resolved (fixed in 1.38.1-3)
bullseye: resolved (fixed in 1.38.1-3)
forky: resolved (fixed in 1.38.1-3)
sid: resolved (fixed in 1.38.1-3)
trixie: resolved (fixed in 1.38.1-3)
Red Hat
gvfs: Incorrect authorization in admin backend allows privileged users to read and modify arbitrary files without prompting for password
vendor_redhat·2018-12-27·CVSS 7.0
CVE-2019-3827 [HIGH] CWE-863 gvfs: Incorrect authorization in admin backend allows privileged users to read and modify arbitrary files without prompting for password
gvfs: Incorrect authorization in admin backend allows privileged users to read and modify arbitrary files without prompting for password
An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious programs running under privileges of users belonging to the wheel group to further escalate its privileges by modifying system files without user's knowledge. Successful exploitation requires uncommon system configuration.
An incorrect permission check in the admin backend in gvfs was found that allows reading and modify arbitrary files by privileged users without asking for passwor
GHSA
GHSA-4782-6x7j-q79q: An incorrect permission check in the admin backend in gvfs before version 1
ghsa_unreviewed·2022-05-13
CVE-2019-3827 [HIGH] CWE-863 GHSA-4782-6x7j-q79q: An incorrect permission check in the admin backend in gvfs before version 1
An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious programs running under privileges of users belonging to the wheel group to further escalate its privileges by modifying system files without user's knowledge. Successful exploitation requires uncommon system configuration.
OSV
CVE-2019-3827: An incorrect permission check in the admin backend in gvfs before version 1
osv·2019-03-25·CVSS 7.0
CVE-2019-3827 [HIGH] CVE-2019-3827: An incorrect permission check in the admin backend in gvfs before version 1
An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious programs running under privileges of users belonging to the wheel group to further escalate its privileges by modifying system files without user's knowledge. Successful exploitation requires uncommon system configuration.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3827 gvfs: Incorrect authorization in admin backend allows privileged users to read and modify arbitrary files without prompting for password [fedora-all]
bugzilla·2019-02-08·CVSS 7.0
CVE-2019-3827 [HIGH] CVE-2019-3827 gvfs: Incorrect authorization in admin backend allows privileged users to read and modify arbitrary files without prompting for password [fedora-all]
CVE-2019-3827 gvfs: Incorrect authorization in admin backend allows privileged users to read and modify arbitrary files without prompting for password [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelo
Bugzilla
CVE-2019-3827 gvfs: Incorrect authorization in admin backend allows privileged users to read and modify arbitrary files without prompting for password
bugzilla·2019-01-11·CVSS 7.0
CVE-2019-3827 [HIGH] CVE-2019-3827 gvfs: Incorrect authorization in admin backend allows privileged users to read and modify arbitrary files without prompting for password
CVE-2019-3827 gvfs: Incorrect authorization in admin backend allows privileged users to read and modify arbitrary files without prompting for password
A flaw was found in gvfs 1.38.1-1. Unprivileged users are not prompted to give password when accessing root owned files.
Upstream issue:
https://gitlab.gnome.org/GNOME/gvfs/issues/355
Upstream patch:
https://gitlab.gnome.org/GNOME/gvfs/merge_requests/31
Discussion:
This flaw affects gvfs since 1.29.4 where admin backend was introduced up to and including 1.39.4.
---
Statement:
This issue did not affect the versions of gvfs as shipped with Red Hat Enterprise Linux 6 as they did not include support for admin backend.
---
Created gvfs tracking bugs for this issue:
Affects: fedora-all [bug 1673885]
---
This issue has been addresse
https://access.redhat.com/errata/RHSA-2019:1517https://access.redhat.com/errata/RHSA-2019:2145https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3827https://gitlab.gnome.org/GNOME/gvfs/merge_requests/31https://access.redhat.com/errata/RHSA-2019:1517https://access.redhat.com/errata/RHSA-2019:2145https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3827https://gitlab.gnome.org/GNOME/gvfs/merge_requests/31
2019-03-25
Published