CVE-2019-3827
Last modified
CVE-2019-3827 is a high-severity vulnerability rated 7/10 on the CVSS scale. An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious programs running under privileges of users belonging to the wheel group to further escalate its privileges by modifying system files without user's knowledge. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious programs running under privileges of users belonging to the wheel group to further escalate its privileges by modifying system files without user's knowledge. Successful exploitation requires uncommon system configuration.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Gvfs | < 1.39.4 |
References
- https://access.redhat.com/errata/RHSA-2019:1517Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2145Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3827Issue Tracking, Patch, Third Party Advisory
- https://gitlab.gnome.org/GNOME/gvfs/merge_requests/31Patch, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:1517Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2145Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3827Issue Tracking, Patch, Third Party Advisory
- https://gitlab.gnome.org/GNOME/gvfs/merge_requests/31Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-3827?
How severe is CVE-2019-3827?
How do I fix CVE-2019-3827?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-3821A flaw was found in the way civetweb frontend was handling r…7.5
- CVE-2019-3822libcurl versions from 7.36.0 to before 7.64.0 are vulnerable…9.8
- CVE-2019-3823libcurl versions from 7.34.0 to before 7.64.0 are vulnerable…4.3
- CVE-2019-3824A flaw was found in the way an LDAP search expression could …
- CVE-2019-3825A vulnerability was discovered in gdm before 3.31.4. When ti…6.3
- CVE-2019-3826A stored, DOM based, cross-site scripting (XSS) flaw was fou…6.1
- CVE-2019-3828Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 h…4.2
- CVE-2019-3829A vulnerability was found in gnutls versions from 3.5.8 befo…5.3
- CVE-2019-3830A vulnerability was found in ceilometer before version 12.0.…7.8
- CVE-2019-3831A vulnerability was discovered in vdsm, version 4.19 through…6.7
- CVE-2019-3832It was discovered the fix for CVE-2018-19758 (libsndfile) wa…5.5
- CVE-2019-3833Openwsman, versions up to and including 2.6.9, are vulnerabl…7.5
Are you affected by CVE-2019-3827?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
