CVE-2019-3827
Last modified
CVE-2019-3827 is a high-severity vulnerability rated 7/10 on the CVSS scale. An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious programs running under privileges of users belonging to the wheel group to further escalate its privileges by modifying system files without user's knowledge. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious programs running under privileges of users belonging to the wheel group to further escalate its privileges by modifying system files without user's knowledge. Successful exploitation requires uncommon system configuration.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Gvfs | < 1.39.4 |
References
- https://access.redhat.com/errata/RHSA-2019:1517Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2145Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3827Issue Tracking, Patch, Third Party Advisory
- https://gitlab.gnome.org/GNOME/gvfs/merge_requests/31Patch, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:1517Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2145Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3827Issue Tracking, Patch, Third Party Advisory
- https://gitlab.gnome.org/GNOME/gvfs/merge_requests/31Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-3827?
How severe is CVE-2019-3827?
How do I fix CVE-2019-3827?
Are you affected by CVE-2019-3827?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
